Authentication Bypass in PaperCut NG by PaperCut Software
CVE-2023-27351
Key Information:
Badges
What is CVE-2023-27351?
A vulnerability exists in PaperCut NG versions 22.0.5 and earlier, allowing remote attackers to bypass authentication without needing to provide valid credentials. This flaw is rooted in the SecurityRequestFilter class and arises from improper implementation of the authentication process. Exploiting this vulnerability enables unauthorized access to the system, putting sensitive information at risk.
CISA has reported CVE-2023-27351
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2023-27351 as being exploited and is known by the CISA as enabling ransomware campaigns.
The CISA's recommendation is: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Affected Version(s)
NG 22.0.5 (Build 63914)
References
EPSS Score
83% chance of being exploited in the next 30 days.
CVSS V3.1
CVSS V3.0
Timeline
- π°
Used in Ransomware
- πΎ
Exploit known to exist
- π¦
CISA Reported
Vulnerability published
Vulnerability Reserved
