The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compromised when email login is enabled on the tenant. Those tenants utilising email login in combination with Microsoft Safe Links or similar are impacted. This vulnerability may allow the attacker to register themselves against a genuine user in the system and allow malicious users with similar access and capabilities via the app to the existing genuine user.
History

Tue, 17 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Nt-ware uniflow Online Print \& Scan
Nt-ware uniflow Smartclient
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:nt-ware:uniflow_online:*:*:*:*:*:-:*:*
cpe:2.3:a:nt-ware:uniflow_online:-:*:*:*:*:chrome:*:*
cpe:2.3:a:nt-ware:uniflow_online_print_\&_scan:-:*:*:*:*:andriod:*:*
cpe:2.3:a:nt-ware:uniflow_online_print_\&_scan:-:*:*:*:*:iphone_os:*:*
cpe:2.3:a:nt-ware:uniflow_smartclient:-:*:*:*:*:macos:*:*
cpe:2.3:a:nt-ware:uniflow_smartclient:-:*:*:*:*:windows:*:*
Vendors & Products Nt-ware uniflow Online Print \& Scan
Nt-ware uniflow Smartclient
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Tue, 03 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Nt-ware
Nt-ware uniflow Online
CPEs cpe:2.3:a:nt-ware:uniflow_online:*:*:*:*:*:*:*:*
Vendors & Products Nt-ware
Nt-ware uniflow Online
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 02 Sep 2024 20:00:00 +0000

Type Values Removed Values Added
Description The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compromised when email login is enabled on the tenant. Those tenants utilising email login in combination with Microsoft Safe Links or similar are impacted. This vulnerability may allow the attacker to register themselves against a genuine user in the system and allow malicious users with similar access and capabilities via the app to the existing genuine user.
Title uniFLOW Online device registration susceptible to compromise
Weaknesses CWE-940
References
Metrics cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Canon_EMEA

Published: 2024-09-02T19:53:10.487Z

Updated: 2024-09-03T14:00:16.816Z

Reserved: 2024-02-19T10:50:12.326Z

Link: CVE-2024-1621

cve-icon Vulnrichment

Updated: 2024-09-03T13:59:38.488Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-02T20:15:03.223

Modified: 2024-09-17T14:12:41.620

Link: CVE-2024-1621

cve-icon Redhat

No data.