Plaintext Storage of a Password
CVE-2022-43958
Summary
A vulnerability has been identified in QMS Automotive (All versions < V12.39), QMS Automotive (All versions < V12.39). User credentials are stored in plaintext in the database without any hashing mechanism. This could allow an attacker to gain access to credentials and impersonate other users.
- LOW
- ADJACENT_NETWORK
- HIGH
- UNCHANGED
- NONE
- LOW
- HIGH
- LOW
CWE-256 - Plaintext Storage of a Password
Storing a password in plaintext may result in a system compromise.
References
Advisory Timeline
- Published