CVE-2023-27350

CRITICAL9.8Pubblicata il 20 aprile 2023

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987.

Sfruttata attivamente

  • Nel catalogo CISA delle vulnerabilità sfruttate dal 21 apr 2023
  • Le agenzie federali statunitensi devono correggerla entro il 12 mag 2023 (direttiva BOD 22-01)
  • Attaccata 3 giorni prima che la vulnerabilità fosse resa pubblica
  • Confermata dai sensori, non solo da segnalazioni
  • Usata in campagne ransomware

Apply updates per vendor instructions.

Fonte: CISA KEV · 26 ago 2026 25 ago 2026 22 ago 2026 21 ago 2026 19 ago 2026 18 ago 2026

Punteggio CVSS9.8 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Tipo di debolezza (CWE)CWE-284
Vendorpapercut

Prodotti coinvolti

VendorProdottoVersioni
papercutpapercut mf< 20.1.7
papercutpapercut ng< 20.1.7

Articoli correlati

This product uses the NVD API but is not endorsed or certified by the NVD.

Database CVE