No analysis available yet.
Vendor Solution
The vulnerability has been fixed by the TCMAN team in version 20250401.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 03 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 02 Dec 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Dec 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unauthorized access vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user exists on the system by using the 'pda:userId' and 'pda:newPassword' parameters with 'soapaction UnlockUser’ in '/WS/PDAWebService.asmx'. | |
| Title | Unauthorized access vulnerability in TCMAN GIM | |
| First Time appeared |
Tcman
Tcman gim |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:tcman:gim:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tcman
Tcman gim |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-12-02T13:25:47.954Z
Reserved: 2025-04-16T09:08:43.217Z
Link: CVE-2025-41012
Updated: 2025-12-02T13:25:44.902Z
Status : Analyzed
Published: 2025-12-02T13:15:53.710
Modified: 2025-12-03T19:46:50.783
Link: CVE-2025-41012
No data.
OpenCVE Enrichment
No data.