CVE Vulnerabilities

CVE-2023-40732

Insufficient Session Expiration

Published: Sep 12, 2023 | Modified: Nov 21, 2024
CVSS 3.x
3.9
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application does not invalidate the session token on logout. This could allow an attacker to perform session hijacking attacks.

Weakness

According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”

Affected Software

Name Vendor Start Version End Version
Qms_automotive Siemens * 12.39 (excluding)

Potential Mitigations

References