CVE-2025-41012
02.12.2025, 13:15
Unauthorized access vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user exists on the system by using the 'pda:userId' and 'pda:newPassword' parameters with 'soapaction UnlockUser in '/WS/PDAWebService.asmx'.Enginsight
| Vendor | Product | Version |
|---|---|---|
| tcman | gim | 𝑥 < 2025-04-01 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration