← All CVEs

CVE-2023-27350

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2023-04-21Remediation due 2023-05-12

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987.

9.8
CVSS
100.0%
EPSS (exploit prob.)
100th
EPSS percentile
2023-04-20
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-284

Affected products

VendorProductAffected versions
papercutpapercut_mf>= 8.0, < 20.1.7
papercutpapercut_mf>= 21.0.0, < 21.2.11
papercutpapercut_mf>= 22.0.0, < 22.0.9
papercutpapercut_ng>= 8.0, < 20.1.7
papercutpapercut_ng>= 21.0.0, < 21.2.11
papercutpapercut_ng>= 22.0.0, < 22.0.9

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-27350