CVE-2023-39143
9.8
CRITICAL · CVSS 3.1 · EPSS 80.1% (pctl 100)
Patch early
EPSS 80.1% — above the 10% action threshold.
Description
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 80.07% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2023-08-04 |
| Last modified | 2026-06-17 |
Affected (3)
| Vendor | Product |
|---|---|
| microsoft | windows |
| papercut | papercut mf |
| papercut | papercut ng |
References
- https://www.horizon3.ai/cve-2023-39143-papercut-path-traversal-file-upload-rce-vulnerability/
- https://www.papercut.com/kb/Main/securitybulletinjuly2023/
- https://www.horizon3.ai/cve-2023-39143-papercut-path-traversal-file-upload-rce-vulnerability/
- https://www.papercut.com/kb/Main/securitybulletinjuly2023/
→ the Explorer · watch your stack · NVD