CVE-2024-1621: uniFLOW Online device registration susceptible to compromise

Published Sep 2, 2024
·
Updated

The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compromised when email login is enabled on the tenant. Those tenants utilising email login in combination with Microsoft Safe Links or similar are impacted. This vulnerability may allow the attacker to register themselves against a genuine user in the system and allow malicious users with similar access and capabilities via the app to the existing genuine user.

Affected Software

6 affected components
NT-ware uniFLOW Online<=2024.1.0
NT-ware Uniflow Online Chrome
NT-ware Uniflow Online Print \& Scan Andriod
NT-ware Uniflow Online Print \& Scan Iphone Os
NT-ware Uniflow Smartclient Macos
NT-ware Uniflow Smartclient Windows

Event History

Sep 2, 2024
CVE Published
via MITRE·07:53 PM
Data Sourced
via MITRE·07:53 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2024-1621?

CVE-2024-1621 has been assigned a medium severity rating due to potential email login compromises.

2

How do I fix CVE-2024-1621?

To mitigate CVE-2024-1621, consider disabling email login or updating to a version of uniFLOW Online after 2024.1.0.

3

Which versions of uniFLOW Online are affected by CVE-2024-1621?

CVE-2024-1621 affects all versions of uniFLOW Online prior to and including version 2024.1.0.

4

What products are impacted by CVE-2024-1621?

CVE-2024-1621 impacts uniFLOW Online, uniFLOW Online Print & Scan for Android and iPhone, and uniFLOW Smartclient for Windows and macOS.

5

Is email login safe in uniFLOW Online versions before 2024.1.0 regarding CVE-2024-1621?

Email login in uniFLOW Online versions prior to 2024.1.0 may expose users to security vulnerabilities due to CVE-2024-1621.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203