Junglewise Threat Intelligence

CVE-2023-27350: PaperCut MF/NG Improper Access Control Vulnerability

CVE-2023-27350 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-04-21

Executive brief

PaperCut MF and NG contain an improper access control vulnerability in the SetupCompleted class. Remote, unauthenticated attackers can bypass authentication to execute arbitrary code with SYSTEM privileges.

Affected products

  • PaperCut PaperCut MF 8.0.0 to 20.1.6, 21.0.0 to 21.2.10, 22.0.0 to 22.0.8
  • PaperCut PaperCut NG 8.0.0 to 20.1.6, 21.0.0 to 21.2.10, 22.0.0 to 22.0.8

Timeline

  • 2023-04-21: disclosed
  • 2023-04-21: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-04-21: advisory

Related threats