CVE-2023-27350
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987.
Aktiv ausgenutzt
- Seit dem 21. Apr. 2023 im CISA-Katalog ausgenutzter Schwachstellen
- US-Bundesbehörden müssen sie bis zum 12. Mai 2023 beheben (BOD 22-01)
- Angegriffen 3 Tage bevor die Schwachstelle öffentlich wurde
- Durch Sensoren bestätigt, nicht nur durch Meldungen
- In Ransomware-Kampagnen eingesetzt
Apply updates per vendor instructions.
Quelle: CISA KEV · 26. Aug. 2026 25. Aug. 2026 22. Aug. 2026 21. Aug. 2026 19. Aug. 2026 18. Aug. 2026
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HBetroffene Produkte
| Hersteller | Prodotto | Versioni |
|---|---|---|
| papercut | papercut mf | < 20.1.7 |
| papercut | papercut ng | < 20.1.7 |
Verwandte Artikel
SchwachstellenZero-Day bei PaperCut NG und MF: aktiv ausgenutzt, alle Versionen gefährdet
Aktiver Zero-Day in PaperCut NG/MF: Alle Versionen gefährdet. Sofortige Gegenmaßnahmen und Indikatoren für Kompromittierungen verfügbar.
SchwachstellenPaperCut unter Beschuss: Zero-Day ausgenutzt, Notfall-Patch und Anweisung, die Server zu isolieren
PaperCut Software hat am 28. August 2026 eine Zero-Day-Schwachstelle in seinen Druckmanagement-Produkten PaperCut NG und PaperCut MF gemeldet, die bereits
This product uses the NVD API but is not endorsed or certified by the NVD.