S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-39143 Scanner

Detects 'Path Traversal' vulnerability in PaperCut NG and PaperCut MF affects v. before 22.1.3.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-39143
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

PaperCut NG and PaperCut MF are software solutions designed to manage and monitor print services for businesses. The former is intended for organizations with up to 5,000 users, while the latter targets those with a larger user base and more complex printing requirements. Serving as an all-in-one print management solution, PaperCut offers features like print tracking, quota allocation, and secure printing.

Recently, security researchers have discovered a critical vulnerability in PaperCut NG and PaperCut MF that exposes these applications to path traversal attacks. The vulnerability is identified as CVE-2023-39143, and it allows attackers to upload, read, or delete arbitrary files, putting the privacy and security of businesses at risk.

If exploited, this vulnerability can enable remote code execution when external device integration is enabled, which is a very common configuration. Attackers can easily gain access to sensitive data and cause havoc by uploading malicious files or deleting important ones. Hackers could potentially take control of a system, posing a severe threat to the confidentiality, integrity, and availability of businesses' printing services.

In conclusion, businesses must take proactive measures to mitigate the risk of path traversal attacks in PaperCut NG and PaperCut MF. Failure to do so can have severe consequences, including loss of sensitive data, system compromise, and reputational damage. Using advanced security tools like s4e.io's pro features can also help businesses to stay up-to-date with emerging vulnerabilities and fortify their digital assets.

 

REFERENCES

Solution Advice

Fortunately, there are several precautions that can be taken to protect against the CVE-2023-39143 vulnerability. Below are some of the necessary measures that businesses should implement:

  • Apply the latest security patches and firmware updates for PaperCut NG and PaperCut MF.
  • Configure external device integration options with the highest level of security and strict access controls.
  • Regularly perform vulnerability assessments and penetration testing to maintain a proactive security posture.
  • Use network segmentation and firewall rules to restrict unauthorized external access to the printing network.
  • Train employees regarding best security practices, including identifying and reporting suspicious activities or messages.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.