KEVIntel
9.8
CVSS
Critical

CVE-2023-27350

PUBLISHED

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication...

Exploited in the wild Used in malware Remote Low complexity No user interaction
Vendor
PaperCut
Product
NG
Published
Apr 20, 2023
EPSS

Description

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987.

cisa malware ransomware nuclei_scanner metasploit

CVSS scores

CVSS v3.0 9.8 Critical

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2023-04-21 00:00:00 UTC · Source

Used in malware

Recorded 2023-04-21 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Apr 21, 2023

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

papercut_ng_auth_bypass

metasploit · Created Unknown

Metasploit module for CVE-2023-27350

monke443/CVE-2023-27350

github · Created 2025-03-09 18:08:42 UTC · 3 stars

Unauthenticated remote command execution in Papercut service allows an attacker to execute commands due to improper access controls in the SetupCompleted Java class.

Jenderal92/CVE-2023-27350

github · Created 2023-06-13 22:13:24 UTC · 0 stars

Python 2.7

ThatNotEasy/CVE-2023-27350

github · Created 2023-05-27 11:32:35 UTC · 2 stars

Perfom With Massive Authentication Bypass In PaperCut MF/NG

adhikara13/CVE-2023-27350

github · Created 2023-04-25 20:51:23 UTC · 8 stars

Exploit for Papercut CVE-2023-27350. [+] Reverse shell [+] Mass checking

horizon3ai/CVE-2023-27350

github · Created 2023-04-22 21:34:06 UTC · 51 stars

Proof of Concept Exploit for PaperCut CVE-2023-27350

imancybersecurity/CVE-2023-27350-POC

github · Created 2023-04-21 20:13:47 UTC · 12 stars

MaanVader/CVE-2023-27350-POC

github · Created 2023-04-21 09:19:13 UTC · 5 stars

A simple python script to check if a service is vulnerable

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Exploit Used in Malware

  • Added to KEVIntel

  • Detected by Nuclei

  • Detected by Metasploit