Successful exploitation of this remotely exploitable vulnerability, which Siemens self-reported, could allow an attacker to read credentials and impersonate authorized users.
All versions of Siemens QMS Automotive, a quality management system suffer from the issue.
In the vulnerability, all versions of Siemens QMS Automotive contain a vulnerability that stores user credentials in plaintext inside the user database. This could allow an attacker to read credentials from memory.
CVE-2022-43958 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.6.
The product sees use mainly in the critical manufacturing sector, and on a global basis.
No known public exploits specifically target this vulnerability. However, an attacker with low skill level could leverage this low complexity vulnerability.
Siemens identified the following specific workarounds and mitigations users can apply to reduce the risk: Enable encryption for user passwords.
As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens’ operational guidelines for industrial security and to follow the recommendations in the product manuals.
For more information, see Siemens Security Advisory SSA-587547.

