CVE-2023-27350

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication...

Basic Information

CVE State
PUBLISHED
Reserved Date
February 28, 2023
Published Date
April 20, 2023
Last Updated
February 03, 2025
Vendor
PaperCut
Product
NG
Description
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987.

CVSS Scores

CVSS v3.0

9.8 - CRITICAL

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2023-04-21 00:00:00 UTC) Source
Proof of Concept Available
Yes (added 2025-03-09 18:08:42 UTC) Source
Used in Malware
Yes (added 2023-04-21 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2023-04-21 00:00:00 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

papercut_ng_auth_bypass

Type: metasploit • Created: Unknown

Metasploit module for CVE-2023-27350

monke443/CVE-2023-27350

Type: github • Created: 2025-03-09 18:08:42 UTC • Stars: 3

Unauthenticated remote command execution in Papercut service allows an attacker to execute commands due to improper access controls in the SetupCompleted Java class.

Jenderal92/CVE-2023-27350

Type: github • Created: 2023-06-13 22:13:24 UTC • Stars: 0

Python 2.7

ThatNotEasy/CVE-2023-27350

Type: github • Created: 2023-05-27 11:32:35 UTC • Stars: 2

Perfom With Massive Authentication Bypass In PaperCut MF/NG

adhikara13/CVE-2023-27350

Type: github • Created: 2023-04-25 20:51:23 UTC • Stars: 8

Exploit for Papercut CVE-2023-27350. [+] Reverse shell [+] Mass checking

horizon3ai/CVE-2023-27350

Type: github • Created: 2023-04-22 21:34:06 UTC • Stars: 51

Proof of Concept Exploit for PaperCut CVE-2023-27350

imancybersecurity/CVE-2023-27350-POC

Type: github • Created: 2023-04-21 20:13:47 UTC • Stars: 12

MaanVader/CVE-2023-27350-POC

Type: github • Created: 2023-04-21 09:19:13 UTC • Stars: 5

A simple python script to check if a service is vulnerable