S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-27350 Scanner

Detects 'Remote Code Execution (RCE)' vulnerability in PaperCut NG affects v. 22.0.5 (Build 63914).

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.3k
Times Used
continuous scan runs
5.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2023-27350
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
NGby PaperCut
22.0.5 (Build 63914)
Updated Aug 22, 2026View on NVD →
Detail

PaperCut NG is a print management software used by many small and large organizations around the world to control, monitor and report on their printing activities. It is a feature-rich solution that ensures the secure and efficient management of printing resources and reduces printing costs. PaperCut NG allows users to track and restrict printing, scanning, and copying activities, set quotas, and provide secure mobile printing options. 

Recently, a severe security flaw has been detected in PaperCut NG, which has been identified as CVE-2023-27350. This vulnerability pertains to a flaw in the SetupCompleted class, which allows unauthorized users to bypass authentication and execute arbitrary code in the context of SYSTEM. The vulnerability arises from inadequate access control measures that are employed by the software. 

When exploited, the CVE-2023-27350 vulnerability can have dire consequences as it provides unauthorized users with complete control over the system. An attacker leveraging this vulnerability can not only bypass authentication, but also gain access to confidential and sensitive information stored on the system, and possibly launch further attacks like installing malware or compromising other hosts in the network. This could result in data loss, system downtime, and a significant financial loss to the organization.

In conclusion, security is critical for any organization, and it is crucial to remain vigilant in the face of emerging vulnerabilities. Thanks to the pro features of s4e.io, users can stay up-to-date on the latest security threats and vulnerabilities in their digital assets, enabling them to take preventative measures before it's too late. Stay secure.

 

REFERENCES

Solution Advice

Fortunately, there are precautions that users can take to protect themselves against this vulnerability. The following measures are recommended:

  • Apply security patches: PaperCut has now released a security patch that addresses this vulnerability. Users are advised to apply the patch as soon as it becomes available to ensure their system is protected.
  • Install anti-virus software: Implementing anti-virus software can detect malicious files and notify users before any damage can be done.
  • Use a firewall: Firewalls help secure networks and prevent unauthorized access to systems. Implementing a firewall can prevent an attacker from exploiting this vulnerability and gaining unauthorized access.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.