CVE-2022-43958

HIGH

QMS Automotive <V12.39 - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in QMS Automotive (All versions < V12.39), QMS Automotive (All versions < V12.39). User credentials are stored in plaintext in the database without any hashing mechanism. This could allow an attacker to gain access to credentials and impersonate other users.

Scores

CVSS v3 7.6
EPSS 0.0010
EPSS Percentile 28.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-312 CWE-256
Status published
Products (1)
siemens/qms_automotive
Published Nov 08, 2022
Tracked Since Feb 18, 2026