Threats Tagged 'cve-2025-41015'
View all threats tagged with 'cve-2025-41015'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-41015'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2025-41015 is a user enumeration vulnerability in TCMAN GIM v11 (version 20250304) that allows unauthenticated attackers to verify the existence of users via the 'pda:username' parameter in the 'soapaction GetUserQuestionAndAnswer' endpoint. This exposure of sensitive information can facilitate further targeted attacks such as phishing or brute force. The vulnerability has a CVSS 4.0 base score of 6.9 (medium severity), indicating moderate risk due to ease of exploitation without authentication and no user interaction required. Although no known exploits are currently in the wild, European organizations using TCMAN GIM should be aware of this risk. Mitigation involves restricting access to the vulnerable web service, implementing rate limiting, and monitoring for suspicious requests. Countries with significant deployments of TCMAN products or critical infrastructure using this system are at higher risk. Prompt patching or vendor guidance should be sought once available. Join the discussion | CVE Database V5 | 12/02/2025, 13:18:25 UTC Added: 12/02/2025, 13:43:15 UTC |
Showing 1 to 1 of 1 result