Information disclosure in QMS Automotive - CVE-2023-40728
Published: September 13, 2023
QMS Automotive
Siemens
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the affected application stores sensitive application data in an external insecure storage wirhin the QMS.Mobile module. A remote attacker can alter content, leading to arbitrary code execution or denial of service (DoS) attack.