CVE-2024-9970: Newtype Flowmaster Bpm Plus

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular privileges can elevate their privileges to administrator by tampering with a specific cookie.

Affected products

  • Newtype Flowmaster Bpm Plus: before 5.3.1 (fixed in 5.3.1)

Published 2024-10-15. Last modified 2026-06-17.