The vendor explicitly identifies these products as affected by this CVE.
- QMS Automotive
- Summary
- The affected application lacks security control to prevent unencrypted communication without HTTPS. An attacker who managed to gain machine-in-the-middle position could manipulate, or steal confidential information.
- Remediation
- Update to V12.39 or later version. The patch is available upon request from customer support
