CVE-2023-40725

CVSS V2 None CVSS V3 None
Description
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application returns inconsistent error messages in response to invalid user credentials during login session. This allows an attacker to enumerate usernames, and identify valid usernames.
Overview
  • CVE ID
  • CVE-2023-40725
  • Assigner
  • siemens
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-09-12T09:32:25.460Z
  • Last Modified Date
  • 2023-09-12T09:32:25.460Z
References
History
Created Old Value New Value Data Type Notes
2024-06-25 02:06:14 Added to TrackCVE