S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-4568 Scanner

Detects 'Unauthenticated XMLRPC Commands Execution' vulnerability in PaperCut NG affects v. 22.0.12 and below.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
4.3k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-4568
6.5
CVSSmedium
Exploitable remotely over the internet · no authentication required.

PaperCut NG allows for unauthenticated XMLRPC commands to be run by default. Versions 22.0.12 and below are confirmed to be affected, but later versions may also be affected due to lack of a vendor supplied patch.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
PaperCut NGby PaperCut
0
Updated Aug 22, 2026View on NVD →
Detail

PaperCut NG is a popular print management software that allows organizations to monitor, control, and manage printing activities. The software provides administrators with a range of tools to effectively manage printing to save costs, reduce waste, and improve productivity. PaperCut NG is commonly used in schools, universities, and businesses with large print volumes to help manage printing resources.

CVE-2023-4568 is a serious vulnerability that has been detected in PaperCut NG. This vulnerability allows for unauthenticated XMLRPC commands to be executed by default, making it easy for hackers to gain access to the system without proper credentials. Versions 22.0.12 and below are confirmed to be affected, but later versions may also be at risk due to the lack of a patch from the vendor.

When exploited, this vulnerability can lead to a range of issues, including data breaches, denial of service attacks, and unauthorized access to sensitive information. Hackers could easily gain access to user data, modify system configurations, or plant malware that could be used to access other systems on the network. The consequences of such an attack could be devastating, leading to reputational damage, financial loss, and legal ramifications.

By using the pro features of the s4e.io platform, those who read this article can easily and quickly learn about vulnerabilities in their digital assets. The platform provides comprehensive security assessments and continuous monitoring to ensure that your systems are protected against the latest threats. With s4e.io, you can be confident that your digital assets are secure and that your organization is protected against attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are several precautions that can be taken by organizations using PaperCut NG. These include:

  • Installing the latest patches and updates from PaperCut NG to ensure that the vulnerability is addressed.
  • Implementing a strong password policy that requires long and complex passwords that are changed regularly.
  • Enabling two-factor authentication to add an extra layer of security to the login process.
  • Monitoring network activity to identify any suspicious activity that could indicate an attack.
  • Conducting regular security audits to identify vulnerabilities and assess the effectiveness of current security measures.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.