Metrics
Affected Vendors & Products
Solution
The vulnerability has been fixed by the TCMAN team. The manufacturer has reported that the vulnerability is not found in the latest version of GIM Web version 20250128.
Workaround
No workaround given by the vendor.
Fri, 11 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Mon, 09 Jun 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 09 Jun 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to modify the permissions held by each of the application's users, including the user himself by sending a POST request to /PC/Options.aspx?Command=2&Page=-1. | |
Title | Incorrect Authorization vulnerability in TCMAN GIM | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-06-09T13:02:46.021Z
Reserved: 2025-04-16T08:38:14.998Z
Link: CVE-2025-40669

Updated: 2025-06-09T13:02:43.600Z

Status : Awaiting Analysis
Published: 2025-06-09T13:15:22.803
Modified: 2025-06-12T16:06:47.857
Link: CVE-2025-40669

No data.

Updated: 2025-06-24T09:51:38Z