peter bassill · operator
$ cve CVE-2023-27350 JSON

CVE-2023-27350 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 100% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2023-05-12.

Description

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS100% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-284
On CISA KEVyes — remediate by 2023-05-12
Public exploityes
Published2023-04-20
Last modified2026-06-17

CISA KEV

NamePaperCut MF/NG Improper Access Control Vulnerability
Added2023-04-21
Due2023-05-12
Vendor / productPaperCut / MF/NG
Ransomware useknown

Affected (2)

VendorProduct
papercutpapercut mf
papercutpapercut ng

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD