PaperCut MF/NG Improper Access Control Vulnerability
Summary
| CVE | CVE-2023-27350 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-20 16:15:00 UTC |
| Updated | 2023-06-07 18:15:00 UTC |
| Description | This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987. |
Risk And Classification
EPSS: 0.942570000 probability, percentile 0.999340000 (date 2026-04-04)
CISA KEV: Listed on 2023-04-21; due 2023-05-12; ransomware use Known
Problem Types: CWE-284
CISA Known Exploited Vulnerability
| Vendor | PaperCut |
|---|---|
| Product | MF/NG |
| Name | PaperCut MF/NG Improper Access Control Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://www.papercut.com/kb/Main/PO-1216-and-PO-1219; https://nvd.nist.gov/vuln/detail/CVE-2023-27350 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Papercut | Papercut Mf | All | All | All | All |
| Application | Papercut | Papercut Ng | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PaperCut PaperCutNG Authentication Bypass ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Increased exploitation of PaperCut drawing blood around the Internet – Sophos News | MISC | news.sophos.com | |
| PaperCut NG/MG 22.0.4 Authentication Bypass ≈ Packet Storm | MISC | packetstormsecurity.com | |
| PaperCut NG/MG 22.0.4 Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| PaperCut MF/NG Authentication Bypass / Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| ZDI-23-233 | Zero Day Initiative | MISC | www.zerodayinitiative.com | |
| APRIL 19 UPDATE | PaperCut MF/NG vulnerability bulletin (March 2023) | PaperCut | MISC | www.papercut.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.