PT-2024-17496 · Papercut · Papercut Ng

Published

2024-03-14

·

Updated

2024-09-26

·

CVE-2024-1223

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PaperCut NG (affected versions not specified)
Description This issue potentially allows unauthorized enumeration of information from the embedded device APIs. An attacker must already have existing knowledge of some combination of valid usernames, device names, and an internal system key. For such an attack to be successful, the system must be in a specific runtime state.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2024-1223
ZDI-24-779

Affected Products

Papercut Ng