CVE-2023-27350 is a critical authentication bypass vulnerability affecting PaperCut NG 22.0.5 (Build 63914) and earlier versions of PaperCut NG/MF. This flaw, stemming from improper access control in the SetupCompleted class, allows unauthenticated remote attackers to bypass authentication and execute arbitrary code with SYSTEM privileges. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, this vulnerability is actively exploited in the wild, including by ransomware groups like Bl00dy and Iranian hacking groups. Publicly available exploit modules and templates exist, and it has garnered significant community discussion and media coverage due to its severe impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0, < 20.1.7CPE matchmatch criteria | cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:* | ||
>= 21.0.0, < 21.2.11CPE matchmatch criteria | cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:* | ||
>= 22.0.0, < 22.0.9CPE matchmatch criteria | cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:* | ||
>= 8.0, < 20.1.7CPE matchmatch criteria | cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:* | ||
>= 21.0.0, < 21.2.11CPE matchmatch criteria | cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.