ZeroHour

CVE-2022-43958

CVSS 3.1
7.6 high
EPSS
<1%p27
Published
()
Modified
Description

A vulnerability has been identified in QMS Automotive (All versions < V12.39), QMS Automotive (All versions < V12.39). User credentials are stored in plaintext in the database without any hashing mechanism. This could allow an attacker to gain access to credentials and impersonate other users.

Vendors
siemens
Products
qms automotive
Weakness
CWE-256, CWE-312
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.