Impact
A session management flaw in the Legacy UI Reduced Function Login of NT‑ware uniFLOW Online allows a previously authenticated session to be retained after logout when specific timing conditions occur during Service Offline Emergency Mode. As a result, a different user can be authenticated as the previous user, gaining unauthorized but limited access to device functionality. The weakness is classified as user impersonation and session fixation (CWE‑613).
Affected Systems
The fault affects NT‑ware uniFLOW Online. No specific impacted version numbers are supplied, but all deployments that enable the Legacy UI Reduced Function Login and Service Offline Emergency Mode are potentially vulnerable.
Risk and Exploitability
The CVSS score is 4.1 and the EPSS score is less than 1%, indicating moderate severity and low exploitation probability. The vulnerability is not listed in CISA KEV. The likely attack vector is a user interaction with the web interface during the narrow timing window of Service Offline Emergency Mode; an attacker can reuse a session cookie after logout to impersonate a former user. Given the limited scope of accessible functions, the impact is confined to a small subset of device controls.
OpenCVE Enrichment