CVE Vulnerabilities

CVE-2023-40732

Insufficient Session Expiration

Published: Sep 12, 2023 | Modified: Sep 14, 2023
CVSS 3.x
3.9
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application does not invalidate the session token on logout. This could allow an attacker to perform session hijacking attacks.

Weakness

According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”

Affected Software

Name Vendor Start Version End Version
Qms_automotive Siemens * 12.39 (excluding)

Potential Mitigations

References