CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

siemens

qms_automotive

11 known vulnerabilities · sorted by CVSS score

CVE-2021-27389
CRITICAL9.8

A vulnerability has been identified in Opcenter Quality (All versions < V12.2), QMS Automotive (All versions < V12.30). A private sign key is shipped with the product without adequate protection.

siemens / opcenter_quality+1
Network
Published Apr 22, 2021
CVE-2023-40726
HIGH8.8

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application server responds with sensitive information about the server. This could allow an attacker to directly access the database.

siemens / qms_automotive
Network
Published Sep 12, 2023
CVE-2023-40727
HIGH7.8

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application uses weak outdated application signing mechanism. This could allow an attacker to tamper the application code.

siemens / qms_automotive
Local
Published Sep 12, 2023
CVE-2022-43958
HIGH7.6

A vulnerability has been identified in QMS Automotive (All versions < V12.39), QMS Automotive (All versions < V12.39). User credentials are stored in plaintext in the database without any hashing mechanism. This could allow an attacker to gain access to credentials and impersonate other users.

siemens / qms_automotive
Adjacent
Published Nov 8, 2022
CVE-2023-40728
HIGH7.3

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application stores sensitive application data in an external insecure storage. This could allow an attacker to alter content, leading to arbitrary code execution or denial-of-service condition.

siemens / qms_automotive
Local
Published Sep 12, 2023
CVE-2023-40729
HIGH7.3

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application lacks security control to prevent unencrypted communication without HTTPS. An attacker who managed to gain machine-in-the-middle position could manipulate, or steal confidential information.

siemens / qms_automotive
Adjacent
Published Sep 12, 2023
CVE-2023-40724
HIGH7.3

A vulnerability has been identified in QMS Automotive (All versions < V12.39). User credentials are found in memory as plaintext. An attacker could perform a memory dump, and get access to credentials, and use it for impersonation.

siemens / qms_automotive
Local
Published Sep 12, 2023
CVE-2023-40730
HIGH7.1

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application lacks sufficient authorization checks. This could allow an attacker to access confidential information, perform administrative functions, or lead to a denial-of-service condition.

siemens / qms_automotive
Network
Published Sep 12, 2023
CVE-2023-40731
MEDIUM5.7

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application allows users to upload arbitrary file types. This could allow an attacker to upload malicious files, that could potentially lead to code tampering.

siemens / qms_automotive
Network
Published Sep 12, 2023
CVE-2023-40725
MEDIUM4.0

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application returns inconsistent error messages in response to invalid user credentials during login session. This allows an attacker to enumerate usernames, and identify valid usernames.

siemens / qms_automotive
Local
Published Sep 12, 2023
CVE-2023-40732
LOW3.9

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application does not invalidate the session token on logout. This could allow an attacker to perform session hijacking attacks.

siemens / qms_automotive
Local
Published Sep 12, 2023