CVE-2023-27351

HIGH(7.5)KEVRansomwareWahrscheinlich ausgenutzt

PaperCut NG/MF Improper Authentication Vulnerability

Beschreibung

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results from improper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-19226.

KEV-Informationen

Hersteller
PaperCut
Produkt
NG/MF
Hinzugefügt am
20. April 2026
Fälligkeitsdatum
4. Mai 2026
Erforderliche Maßnahme
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS-Score

Vektorstring
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NIm Rechner öffnen
Angriffsvektor
NETWORK
Angriffskomplexität
LOW
Erforderliche Privilegien
NONE
Benutzerinteraktion
NONE
Scope
UNCHANGED
Vertraulichkeitsauswirkung
HIGH
Integritätsauswirkung
NONE
Verfügbarkeitsauswirkung
NONE
Ausnutzbarkeitsscore
3.9
Auswirkungsscore
3.6

CWEs

Betroffene Produkte

HerstellerProduktVersion
papercutpapercut mf>= 15.0, < 20.1.7; >= 21.0.0, < 21.2.11; >= 22.0.0, < 22.0.9
papercutpapercut ng>= 15.0, < 20.1.7; >= 21.0.0, < 21.2.11; >= 22.0.0, < 22.0.9

Mehrere CVSS-Bewertungen

Quelle: [email protected](Primary)
7.5
HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Quelle: [email protected](Secondary)
8.2
HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Referenzen

CVSS-Score

7.5
HIGH(7.5)

EPSS-Score

EPSS-Score77.39%
EPSS-Perzentil99.5%

Daten

Veröffentlicht20. April 2023
Zuletzt geändert17. Juni 2026
StatusAnalyzed
CVSS-Versionv3.1

Hilfe beim Schwachstellenmanagement?

Unsere Sicherheitsexperten helfen Ihnen bei der Priorisierung und Behebung von Schwachstellen.