A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application does not invalidate the session token on logout. This could allow an attacker to perform session hijacking attacks.
History

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published: 2023-09-12T09:32:32.841Z

Updated: 2025-02-27T20:55:18.275Z

Reserved: 2023-08-21T10:57:08.486Z

Link: CVE-2023-40732

cve-icon Vulnrichment

Updated: 2024-08-02T18:38:51.290Z

cve-icon NVD

Status : Modified

Published: 2023-09-12T10:15:29.593

Modified: 2024-11-21T08:20:02.943

Link: CVE-2023-40732

cve-icon Redhat

No data.