Search

Find a vulnerability

Search criteria

    4 vulnerabilities found for uniFLOW Online by NT-ware

    CVE-2026-92378 (GCVE-0-2026-92378)

    Vulnerability from nvd – Published: 2026-09-23 07:22 – Updated: 2026-09-23 14:49 X_Cemea X_Nt_Ware X_Subsidiary
    VLAI
    Title
    uniFLOW Online Legacy UI Previous login session retained when entering Reduced Function Login
    Summary
    A session management vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware uniFLOW Online. Under specific timing conditions during Service Offline Emergency Mode, a previously authenticated session may be retained after logout, which could allow a subsequent user to be authenticated as the previous user and gain unauthorised limited access to device functionality.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-23 14:48 UTC
    CWE
    • CWE-613 - Insufficient session expiration
    References
    Impacted products
    Vendor Product Version
    NT-ware uniFLOW Online Affected: 0 , ≤ 2026.2 (custom)
    Create a notification for this product.
    Date Public
    2026-09-23 07:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-92378",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-23T14:48:32.843106Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-23T14:49:17.637Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Web Application"
              ],
              "product": "uniFLOW Online",
              "vendor": "NT-ware",
              "versions": [
                {
                  "lessThanOrEqual": "2026.2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2026-09-23T07:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A session management\nvulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware\nuniFLOW Online. Under specific timing conditions during Service Offline\nEmergency Mode, a previously authenticated session may be retained after\nlogout, which could allow a subsequent user to be authenticated as the previous\nuser and gain unauthorised limited access to device functionality."
                }
              ],
              "value": "A session management\nvulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware\nuniFLOW Online. Under specific timing conditions during Service Offline\nEmergency Mode, a previously authenticated session may be retained after\nlogout, which could allow a subsequent user to be authenticated as the previous\nuser and gain unauthorised limited access to device functionality."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Not applicable"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "PHYSICAL",
                "baseScore": 4.1,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "PASSIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-613",
                  "description": "CWE-613 Insufficient session expiration",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-23T07:22:01.346Z",
            "orgId": "4586e0a2-224d-4f8a-9cb4-8882b208c0b3",
            "shortName": "Canon_EMEA"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.canon-europe.com/psirt/advisory-information/"
            },
            {
              "tags": [
                "vendor-advisory",
                "mitigation"
              ],
              "url": "https://ntware.atlassian.net/wiki/spaces/SA/pages/14160592897/Security+Advisory+Previous+login+session+retained+when+entering+Reduced+Function+Login"
            }
          ],
          "source": {
            "advisory": "CPE2026-055",
            "discovery": "EXTERNAL"
          },
          "tags": [
            "x_cemea",
            "x_nt_ware",
            "x_subsidiary"
          ],
          "title": "uniFLOW Online Legacy UI Previous login session retained when entering Reduced Function Login",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4586e0a2-224d-4f8a-9cb4-8882b208c0b3",
        "assignerShortName": "Canon_EMEA",
        "cveId": "CVE-2026-92378",
        "datePublished": "2026-09-23T07:22:01.346Z",
        "dateReserved": "2026-09-16T07:22:01.696Z",
        "dateUpdated": "2026-09-23T14:49:17.637Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-1621 (GCVE-0-2024-1621)

    Vulnerability from nvd – Published: 2024-09-02 19:53 – Updated: 2024-09-03 14:00 X_Nt_Ware
    VLAI
    Title
    uniFLOW Online device registration susceptible to compromise
    Summary
    The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compromised when email login is enabled on the tenant. Those tenants utilising email login in combination with Microsoft Safe Links or similar are impacted. This vulnerability may allow the attacker to register themselves against a genuine user in the system and allow malicious users with similar access and capabilities via the app to the existing genuine user.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-03 13:57 UTC
    CWE
    • CWE-940 - Improper Verification of Source of a Communication Channel
    References
    Impacted products
    Vendor Product Version
    NT-ware uniFLOW Online Affected: 0 , ≤ 2024.1.0 (including) (custom)
    Create a notification for this product.
    nt-ware uniflow_online Affected: 0 , ≤ 2024.1.0 (custom)
        cpe:2.3:a:nt-ware:uniflow_online:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-09-02 19:52
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:nt-ware:uniflow_online:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "uniflow_online",
                "vendor": "nt-ware",
                "versions": [
                  {
                    "lessThanOrEqual": "2024.1.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-1621",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-03T13:57:32.174095Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-03T14:00:16.816Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "uniFLOW SmartClient",
                "Mobile Application",
                "Chrome Extension"
              ],
              "product": "uniFLOW Online",
              "vendor": "NT-ware",
              "versions": [
                {
                  "lessThanOrEqual": "2024.1.0 (including)",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2024-09-02T19:52:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compromised when email login is enabled on the tenant. Those tenants utilising email login in combination with Microsoft Safe Links or similar are impacted. This vulnerability may allow the attacker to register themselves against a genuine user in the system and allow malicious users with similar access and capabilities via the app to the existing genuine user."
                }
              ],
              "value": "The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compromised when email login is enabled on the tenant. Those tenants utilising email login in combination with Microsoft Safe Links or similar are impacted. This vulnerability may allow the attacker to register themselves against a genuine user in the system and allow malicious users with similar access and capabilities via the app to the existing genuine user."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Not applicable"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 8.3,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-940",
                  "description": "CWE-940: Improper Verification of Source of a Communication Channel",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-02T19:53:10.487Z",
            "orgId": "4586e0a2-224d-4f8a-9cb4-8882b208c0b3",
            "shortName": "Canon_EMEA"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "mitigation"
              ],
              "url": "https://ntware.atlassian.net/wiki/spaces/SA/pages/12113215492/2024+Security+Advisory+Device+registration+susceptible+to+compromise"
            },
            {
              "tags": [
                "vendor-advisory",
                "mitigation"
              ],
              "url": "https://www.canon-europe.com/psirt/advisory-information/"
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "tags": [
            "x_nt_ware"
          ],
          "title": "uniFLOW Online device registration susceptible to compromise",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4586e0a2-224d-4f8a-9cb4-8882b208c0b3",
        "assignerShortName": "Canon_EMEA",
        "cveId": "CVE-2024-1621",
        "datePublished": "2024-09-02T19:53:10.487Z",
        "dateReserved": "2024-02-19T10:50:12.326Z",
        "dateUpdated": "2024-09-03T14:00:16.816Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2026-92378 (GCVE-0-2026-92378)

    Vulnerability from cvelistv5 – Published: 2026-09-23 07:22 – Updated: 2026-09-23 14:49 X_Cemea X_Nt_Ware X_Subsidiary
    VLAI
    Title
    uniFLOW Online Legacy UI Previous login session retained when entering Reduced Function Login
    Summary
    A session management vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware uniFLOW Online. Under specific timing conditions during Service Offline Emergency Mode, a previously authenticated session may be retained after logout, which could allow a subsequent user to be authenticated as the previous user and gain unauthorised limited access to device functionality.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-23 14:48 UTC
    CWE
    • CWE-613 - Insufficient session expiration
    References
    Impacted products
    Vendor Product Version
    NT-ware uniFLOW Online Affected: 0 , ≤ 2026.2 (custom)
    Create a notification for this product.
    Date Public
    2026-09-23 07:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-92378",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-23T14:48:32.843106Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-23T14:49:17.637Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Web Application"
              ],
              "product": "uniFLOW Online",
              "vendor": "NT-ware",
              "versions": [
                {
                  "lessThanOrEqual": "2026.2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2026-09-23T07:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A session management\nvulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware\nuniFLOW Online. Under specific timing conditions during Service Offline\nEmergency Mode, a previously authenticated session may be retained after\nlogout, which could allow a subsequent user to be authenticated as the previous\nuser and gain unauthorised limited access to device functionality."
                }
              ],
              "value": "A session management\nvulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware\nuniFLOW Online. Under specific timing conditions during Service Offline\nEmergency Mode, a previously authenticated session may be retained after\nlogout, which could allow a subsequent user to be authenticated as the previous\nuser and gain unauthorised limited access to device functionality."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Not applicable"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "PHYSICAL",
                "baseScore": 4.1,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "PASSIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-613",
                  "description": "CWE-613 Insufficient session expiration",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-23T07:22:01.346Z",
            "orgId": "4586e0a2-224d-4f8a-9cb4-8882b208c0b3",
            "shortName": "Canon_EMEA"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.canon-europe.com/psirt/advisory-information/"
            },
            {
              "tags": [
                "vendor-advisory",
                "mitigation"
              ],
              "url": "https://ntware.atlassian.net/wiki/spaces/SA/pages/14160592897/Security+Advisory+Previous+login+session+retained+when+entering+Reduced+Function+Login"
            }
          ],
          "source": {
            "advisory": "CPE2026-055",
            "discovery": "EXTERNAL"
          },
          "tags": [
            "x_cemea",
            "x_nt_ware",
            "x_subsidiary"
          ],
          "title": "uniFLOW Online Legacy UI Previous login session retained when entering Reduced Function Login",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4586e0a2-224d-4f8a-9cb4-8882b208c0b3",
        "assignerShortName": "Canon_EMEA",
        "cveId": "CVE-2026-92378",
        "datePublished": "2026-09-23T07:22:01.346Z",
        "dateReserved": "2026-09-16T07:22:01.696Z",
        "dateUpdated": "2026-09-23T14:49:17.637Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-1621 (GCVE-0-2024-1621)

    Vulnerability from cvelistv5 – Published: 2024-09-02 19:53 – Updated: 2024-09-03 14:00 X_Nt_Ware
    VLAI
    Title
    uniFLOW Online device registration susceptible to compromise
    Summary
    The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compromised when email login is enabled on the tenant. Those tenants utilising email login in combination with Microsoft Safe Links or similar are impacted. This vulnerability may allow the attacker to register themselves against a genuine user in the system and allow malicious users with similar access and capabilities via the app to the existing genuine user.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-03 13:57 UTC
    CWE
    • CWE-940 - Improper Verification of Source of a Communication Channel
    References
    Impacted products
    Vendor Product Version
    NT-ware uniFLOW Online Affected: 0 , ≤ 2024.1.0 (including) (custom)
    Create a notification for this product.
    nt-ware uniflow_online Affected: 0 , ≤ 2024.1.0 (custom)
        cpe:2.3:a:nt-ware:uniflow_online:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-09-02 19:52
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:nt-ware:uniflow_online:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "uniflow_online",
                "vendor": "nt-ware",
                "versions": [
                  {
                    "lessThanOrEqual": "2024.1.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-1621",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-03T13:57:32.174095Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-03T14:00:16.816Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "uniFLOW SmartClient",
                "Mobile Application",
                "Chrome Extension"
              ],
              "product": "uniFLOW Online",
              "vendor": "NT-ware",
              "versions": [
                {
                  "lessThanOrEqual": "2024.1.0 (including)",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2024-09-02T19:52:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compromised when email login is enabled on the tenant. Those tenants utilising email login in combination with Microsoft Safe Links or similar are impacted. This vulnerability may allow the attacker to register themselves against a genuine user in the system and allow malicious users with similar access and capabilities via the app to the existing genuine user."
                }
              ],
              "value": "The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compromised when email login is enabled on the tenant. Those tenants utilising email login in combination with Microsoft Safe Links or similar are impacted. This vulnerability may allow the attacker to register themselves against a genuine user in the system and allow malicious users with similar access and capabilities via the app to the existing genuine user."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Not applicable"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 8.3,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-940",
                  "description": "CWE-940: Improper Verification of Source of a Communication Channel",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-02T19:53:10.487Z",
            "orgId": "4586e0a2-224d-4f8a-9cb4-8882b208c0b3",
            "shortName": "Canon_EMEA"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "mitigation"
              ],
              "url": "https://ntware.atlassian.net/wiki/spaces/SA/pages/12113215492/2024+Security+Advisory+Device+registration+susceptible+to+compromise"
            },
            {
              "tags": [
                "vendor-advisory",
                "mitigation"
              ],
              "url": "https://www.canon-europe.com/psirt/advisory-information/"
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "tags": [
            "x_nt_ware"
          ],
          "title": "uniFLOW Online device registration susceptible to compromise",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4586e0a2-224d-4f8a-9cb4-8882b208c0b3",
        "assignerShortName": "Canon_EMEA",
        "cveId": "CVE-2024-1621",
        "datePublished": "2024-09-02T19:53:10.487Z",
        "dateReserved": "2024-02-19T10:50:12.326Z",
        "dateUpdated": "2024-09-03T14:00:16.816Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }