CVE Feed

    Dashboard / CVE / CVE-2024-1621

    CVE-2024-1621

    The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compromised when email login is enabled on the tenant. Those tenants utilising email login in combination with Microsoft Safe Links or similar are impacted. This vulnerability may allow the attacker to register themselves against a genuine user in the system and allow malicious users with similar access and capabilities via the app to the existing genuine user.

    Published:Sep 2, 2024
    Last Modified:Sep 17, 2024
    EPS:Sep 2, 2024
    EPSS Score:0.00132
    CVSS Score:7.5

    Affected Products

    Vendor
    Nt-ware
    Product
    Uniflow Online
    Vendor
    Nt-ware
    Product
    Uniflow Online Print \& Scan
    Vendor
    Nt-ware
    Product
    Uniflow Smartclient

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High