Executive brief
PaperCut MF and NG contain an improper access control vulnerability in the SetupCompleted class. Remote, unauthenticated attackers can bypass authentication to execute arbitrary code with SYSTEM privileges.
Affected products
- PaperCut PaperCut MF 8.0.0 to 20.1.6, 21.0.0 to 21.2.10, 22.0.0 to 22.0.8
- PaperCut PaperCut NG 8.0.0 to 20.1.6, 21.0.0 to 21.2.10, 22.0.0 to 22.0.8
Timeline
- 2023-04-21: disclosed
- 2023-04-21: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-04-21: advisory