Improper access control in PaperCut MF and PaperCut NG - #VU74037
Published: March 27, 2023
Vulnerability identifier: #VU74037
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions within the SetupCompleted class. A remote attacker can bypass implemented security restrictions and execute arbitrary code on the target system.
Affected software
PaperCut MF
PaperCut NG
PaperCut NG
Remediation
Install updates from vendor's website.
PaperCut MF - addressed in versions 20.1.7, 21.2.11, 22.0.9
PaperCut NG - addressed in versions 20.1.7, 21.2.11, 22.0.9
PaperCut NG - addressed in versions 20.1.7, 21.2.11, 22.0.9