ZeroHour

CVE-2023-40725

CVSS 3.1
4.0 medium
EPSS
<1%p7
Published
()
Modified
Description

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application returns inconsistent error messages in response to invalid user credentials during login session. This allows an attacker to enumerate usernames, and identify valid usernames.

Vendors
siemens
Products
qms automotive
Weakness
CWE-209
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.