PT-2023-2482 · Unknown · Papercut Ng

Publicado

2023-03-14

·

Atualizado

2026-04-21

·

CVE-2023-27350

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
The vulnerable software is PaperCut NG, specifically version 22.0.5 (Build 63914). This version is affected by an improper access control flaw in the SetupCompleted class, which allows remote attackers to bypass authentication and execute arbitrary code in the context of SYSTEM. An exploit for this issue exists and has been used by malicious software such as LockBit and Clop. The issue can be exploited without requiring authentication, making it a significant concern for users of the affected software. There are approximately 4,929 results related to this vulnerability on ZoomEye, indicating a potentially large number of affected systems. More information about the exploit can be found on various online platforms, including Reddit and TryHackMe. https://www.reddit.com/r/netsec/comments/12xc9r7/papercut cve202327350 deep dive indicators of/ #PaperCut #RemoteCodeExecution #ImproperAccessControl #Cybersecurity #TryHackMe #Exploit #LockBit #Clop #ZoomEye

Exploit

Correção

RCE

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-02273
CVE-2023-27350
ZDI-23-233

Produtos afetados

Papercut Ng