Metrics
Affected Vendors & Products
No advisories yet.
Solution
The vulnerability has been fixed by the TCMAN team in version 20250401.
Workaround
No workaround given by the vendor.
Tue, 02 Dec 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Dec 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unauthorized access vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user exists on the system by using the 'pda:userId' and 'pda:newPassword' parameters with 'soapaction UnlockUser’ in '/WS/PDAWebService.asmx'. | |
| Title | Unauthorized access vulnerability in TCMAN GIM | |
| First Time appeared |
Tcman
Tcman gim |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:tcman:gim:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tcman
Tcman gim |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-12-02T13:25:47.954Z
Reserved: 2025-04-16T09:08:43.217Z
Link: CVE-2025-41012
Updated: 2025-12-02T13:25:44.902Z
Status : Received
Published: 2025-12-02T13:15:53.710
Modified: 2025-12-02T13:15:53.710
Link: CVE-2025-41012
No data.
OpenCVE Enrichment
No data.