ZeroHour

CVE-2023-40732

CVSS 3.1
3.9 low
EPSS
<1%p4
Published
()
Modified
Description

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application does not invalidate the session token on logout. This could allow an attacker to perform session hijacking attacks.

Vendors
siemens
Products
qms automotive
Weakness
CWE-613
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.