CVE-2024-47076 is a critical vulnerability in openprinting libcupsfilters, specifically within the cfGetPrinterAttributes5 function. This flaw allows an unauthenticated attacker to inject malicious IPP attributes, leading to attacker-controlled data being processed by the CUPS system. With a CVSS score of 8.6 (HIGH), this vulnerability poses a significant risk of remote code execution (RCE) due to its network-based attack vector and low attack complexity. While not yet in the KEV catalog, a Metasploit module for RCE exists, and the vulnerability has garnered substantial community discussion and media coverage, indicating high awareness and potential for active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.0CPE matchmatch criteria | cpe:2.3:a:openprinting:libcupsfilters:*:*:*:*:*:*:*:* | ||
2.1CPE matchmatch criteria | cpe:2.3:a:openprinting:libcupsfilters:2.1:beta1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025cups-filters: libcupsfilters: `cfGetPrinterAttributes` API does not perform sanitization on returned IPP attributes
Sep 26, 2024