Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-17457 | Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to modify the permissions held by each of the application's users, including the user himself by sending a POST request to /PC/Options.aspx?Command=2&Page=-1. |
Solution
The vulnerability has been fixed by the TCMAN team. The manufacturer has reported that the vulnerability is not found in the latest version of GIM Web version 20250128.
Workaround
No workaround given by the vendor.
Tue, 07 Oct 2025 04:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:tcman:gim:11.0:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Fri, 11 Jul 2025 22:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 09 Jun 2025 22:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Jun 2025 21:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to modify the permissions held by each of the application's users, including the user himself by sending a POST request to /PC/Options.aspx?Command=2&Page=-1. | |
| Title | Incorrect Authorization vulnerability in TCMAN GIM | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-06-09T13:02:46.021Z
Reserved: 2025-04-16T08:38:14.998Z
Link: CVE-2025-40669
Updated: 2025-06-09T13:02:43.600Z
Status : Analyzed
Published: 2025-06-09T13:15:22.803
Modified: 2025-10-06T19:37:27.340
Link: CVE-2025-40669
No data.
OpenCVE Enrichment
Updated: 2025-06-24T18:51:38Z
EUVD