CVE-2021-40853 HIGH

CVE-2021-40853: TCMAN GIM missing authorization vulnerability

Vendor Tcman
Product GIM
Weakness CWE-862 · Missing authorization
Published December 17, 2021
Last update September 17, 2024

CVSS base score

7.2/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

TCMAN GIM does not perform an authorization check when trying to access determined resources. A remote attacker could exploit this vulnerability to access URL that require privileges without having them. The exploitation of this vulnerability might allow a remote attacker to obtain sensible information.

Key dates

02Disclosure timeline

December 17, 2021 CVE published
September 17, 2024 Record updated