The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compromised when email login is enabled on the tenant. Those tenants utilising email login in combination with Microsoft Safe Links or similar are impacted. This vulnerability may allow the attacker to register themselves against a genuine user in the system and allow malicious users with similar access and capabilities via the app to the existing genuine user.
Metrics
Affected Vendors & Products
References
History
Tue, 17 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Nt-ware uniflow Online Print \& Scan
Nt-ware uniflow Smartclient |
|
Weaknesses | NVD-CWE-Other | |
CPEs | cpe:2.3:a:nt-ware:uniflow_online:*:*:*:*:*:-:*:* cpe:2.3:a:nt-ware:uniflow_online:-:*:*:*:*:chrome:*:* cpe:2.3:a:nt-ware:uniflow_online_print_\&_scan:-:*:*:*:*:andriod:*:* cpe:2.3:a:nt-ware:uniflow_online_print_\&_scan:-:*:*:*:*:iphone_os:*:* cpe:2.3:a:nt-ware:uniflow_smartclient:-:*:*:*:*:macos:*:* cpe:2.3:a:nt-ware:uniflow_smartclient:-:*:*:*:*:windows:*:* |
|
Vendors & Products |
Nt-ware uniflow Online Print \& Scan
Nt-ware uniflow Smartclient |
|
Metrics |
cvssV3_1
|
Tue, 03 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Nt-ware
Nt-ware uniflow Online |
|
CPEs | cpe:2.3:a:nt-ware:uniflow_online:*:*:*:*:*:*:*:* | |
Vendors & Products |
Nt-ware
Nt-ware uniflow Online |
|
Metrics |
ssvc
|
Mon, 02 Sep 2024 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compromised when email login is enabled on the tenant. Those tenants utilising email login in combination with Microsoft Safe Links or similar are impacted. This vulnerability may allow the attacker to register themselves against a genuine user in the system and allow malicious users with similar access and capabilities via the app to the existing genuine user. | |
Title | uniFLOW Online device registration susceptible to compromise | |
Weaknesses | CWE-940 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: Canon_EMEA
Published: 2024-09-02T19:53:10.487Z
Updated: 2024-09-03T14:00:16.816Z
Reserved: 2024-02-19T10:50:12.326Z
Link: CVE-2024-1621
Vulnrichment
Updated: 2024-09-03T13:59:38.488Z
NVD
Status : Analyzed
Published: 2024-09-02T20:15:03.223
Modified: 2024-09-17T14:12:41.620
Link: CVE-2024-1621
Redhat
No data.