CVE Vulnerabilities

CVE-2022-43958

Plaintext Storage of a Password

Published: Nov 08, 2022 | Modified: Nov 21, 2024
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability has been identified in QMS Automotive (All versions < V12.39), QMS Automotive (All versions < V12.39). User credentials are stored in plaintext in the database without any hashing mechanism. This could allow an attacker to gain access to credentials and impersonate other users.

Weakness

The product stores a password in plaintext within resources such as memory or files.

Affected Software

Name Vendor Start Version End Version
Qms_automotive Siemens * *

Potential Mitigations

References