CVE-2024-1621 Vulnerability Details

  /     /     /  

CVE-2024-1621 Metadata Quick Info

CVE Published: 02/09/2024 | CVE Updated: 03/09/2024 | CVE Year: 2024
Source: Canon_EMEA | Vendor: NT-ware | Product: uniFLOW Online
Status : PUBLISHED

CVE-2024-1621 Description

The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compromised when email login is enabled on the tenant. Those tenants utilising email login in combination with Microsoft Safe Links or similar are impacted. This vulnerability may allow the attacker to register themselves against a genuine user in the system and allow malicious users with similar access and capabilities via the app to the existing genuine user.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-940
CWE Name: CWE-940: Improper Verification of Source of a Communication Channel
Source: NT-ware

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description: Not applicable


Source: NVD (National Vulnerability Database).