PT-2025-48680 · Tcman Gim · Tcman Gim

Published

2025-12-02

·

Updated

2025-12-03

·

CVE-2025-41012

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions TCMAN GIM version 20250304
Description An unauthenticated attacker can determine if a user exists on the system. This is achieved by utilizing the pda:userId and pda:newPassword parameters with the 'soapaction UnlockUser’ within the '/WS/PDAWebService.asmx' endpoint.
Recommendations Apply restrictions to the '/WS/PDAWebService.asmx' API endpoint. Avoid using the pda:userId and pda:newPassword parameters.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-41012

Affected Products

Tcman Gim