Metrics
Affected Vendors & Products
Solution
The vulnerability has been fixed by the TCMAN team. The manufacturer has reported that the vulnerability is not found in the latest version of GIM Web version 20250128.
Workaround
No workaround given by the vendor.
Fri, 11 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Mon, 09 Jun 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 09 Jun 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an attacker, with low privilege level, to change the password of other users through a POST request using the parameters idUser, PasswordActual, PasswordNew and PasswordNewRepeat in /PC/WebService.aspx/validateChangePassword%C3%B1a. To exploit the vulnerability the PasswordActual parameter must be empty. | |
Title | Incorrect Authorization vulnerability in TCMAN GIM | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-06-09T13:03:21.122Z
Reserved: 2025-04-16T08:38:14.998Z
Link: CVE-2025-40668

Updated: 2025-06-09T13:03:17.609Z

Status : Awaiting Analysis
Published: 2025-06-09T13:15:22.633
Modified: 2025-06-12T16:06:47.857
Link: CVE-2025-40668

No data.

Updated: 2025-06-23T09:16:30Z