Metrics
Affected Vendors & Products
Solution
The vulnerability has been fixed by the TCMAN team. The manufacturer has reported that the vulnerability is not found in the latest version of GIM Web version 20250128.
Workaround
No workaround given by the vendor.
Fri, 11 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Mon, 09 Jun 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 09 Jun 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to create a user and assign it many privileges by sending a POST request to /PC/frmGestionUser.aspx/updateUser. | |
Title | Incorrect Authorization vulnerability in TCMAN GIM | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-06-09T13:01:52.381Z
Reserved: 2025-04-16T08:38:14.998Z
Link: CVE-2025-40670

Updated: 2025-06-09T13:01:50.079Z

Status : Awaiting Analysis
Published: 2025-06-09T13:15:22.963
Modified: 2025-06-12T16:06:47.857
Link: CVE-2025-40670

No data.

Updated: 2025-06-24T09:44:12Z