CVE-2023-40726
Siemens Qms Automotive ≤ 12.39
Raw vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2023-40726 is a high-severity Server-generated Error Message Containing Sensitive Information (CWE-550) vulnerability in Siemens Qms Automotive. Its CVSS base score is 8.8 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique System Information Discovery (T1082); ranked at the 44th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-45280
Vulnerability Data
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application server responds with sensitive information about the server. This could allow an attacker to directly access the database.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
—
V14.2.1
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing can detect and require remediation of verbose error messages.
Logging policy can require suppression of sensitive data in error responses.
Secure SDLC mandates handling of error messages to avoid information disclosure.
Application security requirements can specify safe error handling and generic messages.
Secure architecture principles include proper exception handling to prevent leakage.
Secure coding standards prohibit embedding sensitive data in server error messages.