PaperCut Vulnerabilities and Affected Products
Vulnerabilities associated with NG/MF.
Products
Clear product- PaperCut NG, PaperCut MF12 vulnerabilities
- papercut_ng8 vulnerabilities
- PaperCut NG/MF7 vulnerabilities
- papercut_mf7 vulnerabilities
- NG4 vulnerabilities
- NG/MF2 vulnerabilities
- PaperCut NG2 vulnerabilities
- Print Deploy2 vulnerabilities
- MF/NG1 vulnerability
- PaperCut Hive1 vulnerability
- PaperCut MF1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-2533HIGH | PaperCut MF/NG 22.0.10 (Build 65996 2023-03-27) - Remote code execution via CSRFA Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code. This could be exploited if the target is an admin with a current login session. Exploiting this would typically involve the possibility of deceiving an admin into clicking a specially crafted malicious link, potentially leading to unauthorized changes. CWE-352Jun 20, 2023 | CVSS8.4v3.1 | EPSS29.2% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-27351HIGH | PaperCut NG/MF Improper Authentication VulnerabilityThis vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results from improper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-19226. | CVSS7.5v3.1 | EPSS77.4% | PoCs0 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |