uniFLOW Online Legacy UI Previous login session retained when entering Reduced Function Login
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 4.1epss 0.2%
probabilidade de exploração
0.2%top 93% das CVEs
exploração observada
nãonenhuma fonte reporta
A session management
vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware
uniFLOW Online. Under specific timing conditions during Service Offline
Emergency Mode, a previously authenticated session may be retained after
logout, which could allow a subsequent user to be authenticated as the previous
user and gain unauthorised limited access to device functionality.
CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Produtos afetados
NT-ware · uniFLOW Online