VYPR
Medium severity5.3NVD Advisory· Published Dec 2, 2025· Updated Jun 17, 2026

CVE-2025-41012

CVE-2025-41012

Description

Unauthorized access vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user exists on the system by using the 'pda:userId' and 'pda:newPassword' parameters with 'soapaction UnlockUser’ in '/WS/PDAWebService.asmx'.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • TCMAN/GIM3 versions
    cpe:2.3:a:tcman:gim:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:tcman:gim:*:*:*:*:*:*:*:*range: <2025-04-01
    • (no CPE)range: 20250304
    • (no CPE)range: 0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.