CVE-2024-1621: uniFLOW Online device registration susceptible to compromise
The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compromised when email login is enabled on the tenant. Those tenants utilising email login in combination with Microsoft Safe Links or similar are impacted. This vulnerability may allow the attacker to register themselves against a genuine user in the system and allow malicious users with similar access and capabilities via the app to the existing genuine user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1621?
CVE-2024-1621 has been assigned a medium severity rating due to potential email login compromises.
How do I fix CVE-2024-1621?
To mitigate CVE-2024-1621, consider disabling email login or updating to a version of uniFLOW Online after 2024.1.0.
Which versions of uniFLOW Online are affected by CVE-2024-1621?
CVE-2024-1621 affects all versions of uniFLOW Online prior to and including version 2024.1.0.
What products are impacted by CVE-2024-1621?
CVE-2024-1621 impacts uniFLOW Online, uniFLOW Online Print & Scan for Android and iPhone, and uniFLOW Smartclient for Windows and macOS.
Is email login safe in uniFLOW Online versions before 2024.1.0 regarding CVE-2024-1621?
Email login in uniFLOW Online versions prior to 2024.1.0 may expose users to security vulnerabilities due to CVE-2024-1621.