9.8

CVE-2023-27350

Warnung
Medienbericht
Exploit
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Papercut ≫ Papercut Mf Version >= 8.0 < 20.1.7
Papercut ≫ Papercut Mf Version >= 21.0.0 < 21.2.11
Papercut ≫ Papercut Mf Version >= 22.0.0 < 22.0.9
Papercut ≫ Papercut Ng Version >= 8.0 < 20.1.7
Papercut ≫ Papercut Ng Version >= 21.0.0 < 21.2.11
Papercut ≫ Papercut Ng Version >= 22.0.0 < 22.0.9

21.04.2023: CISA Known Exploited Vulnerabilities (KEV) Catalog

PaperCut MF/NG Improper Access Control Vulnerability

Schwachstelle

PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of system.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 100% 1
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Trend Micro 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
28.08.2026 21:33
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
28.08.2026 11:03
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
27.08.2026 18:33
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
10.04.2026 15:19
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
06.04.2026 19:00
http://packetstormsecurity.com/files/171982/PaperCut-MF-NG-Authentication-Bypass-Remote-Code-Execution.html
Third Party Advisory
VDB Entry
http://packetstormsecurity.com/files/172022/PaperCut-NG-MG-22.0.4-Authentication-Bypass.html
Third Party Advisory
Exploit
VDB Entry
http://packetstormsecurity.com/files/172512/PaperCut-NG-MG-22.0.4-Remote-Code-Execution.html
Third Party Advisory
Exploit
VDB Entry
http://packetstormsecurity.com/files/172780/PaperCut-PaperCutNG-Authentication-Bypass.html
Third Party Advisory
Exploit
VDB Entry
https://news.sophos.com/en-us/2023/04/27/increased-exploitation-of-papercut-drawing-blood-around-the-internet/
Third Party Advisory
https://www.papercut.com/kb/Main/PO-1216-and-PO-1219
Vendor Advisory
https://www.zerodayinitiative.com/advisories/ZDI-23-233/
Third Party Advisory
VDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-27350
US Government Resource