CVE-2021-40852
MEDIUMCVSS 6.1/10EPSS 0.72%
Last modified
CVE-2021-40852 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. TCMAN GIM is affected by an open redirect vulnerability. This vulnerability allows the redirection of user navigation to pages controlled by the attacker. EPSS estimates a 0.72% chance of exploitation in the next 30 days.
Description
TCMAN GIM is affected by an open redirect vulnerability. This vulnerability allows the redirection of user navigation to pages controlled by the attacker. The exploitation of this vulnerability might allow a remote attacker to obtain information.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tcman | Gim | 8.0 |
| Tcman | Gim | 11.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-40852?
TCMAN GIM is affected by an open redirect vulnerability. This vulnerability allows the redirection of user navigation to pages controlled by the attacker. The exploitation of this vulnerability might allow a remote attacker to obtain information.
How severe is CVE-2021-40852?
CVE-2021-40852 has a CVSS score of 6.1/10 (MEDIUM severity). The EPSS model estimates a 0.72% probability of exploitation in the next 30 days.
How do I fix CVE-2021-40852?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-40846An issue was discovered in Rhinode Trading Paints through 2.…7.5
- CVE-2021-40847The update process of the Circle Parental Control Service on…8.1
- CVE-2021-40848In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exp…7.8
- CVE-2021-40849In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the…9.8
- CVE-2021-40850TCMAN GIM is vulnerable to a SQL injection vulnerability ins…9.8
- CVE-2021-40851TCMAN GIM is vulnerable to a lack of authorization in all av…7.5
- CVE-2021-40853TCMAN GIM does not perform an authorization check when tryin…7.2
- CVE-2021-40854AnyDesk before 6.2.6 and 6.3.x before 6.3.3 allows a local u…7.8
- CVE-2021-40855The EU Technical Specifications for Digital COVID Certificat…9.8
- CVE-2021-40856Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices …7.5
- CVE-2021-40857Auerswald COMpact 5500R devices before 8.2B allow Privilege …8.8
- CVE-2021-40858Auerswald COMpact 5500R devices before 8.2B allow Arbitrary …4.9
Are you affected by CVE-2021-40852?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
