PT-2024-6705 · Unknown · Papercut Ng/Mf

Amol Dosanjh

·

Published

2024-05-14

·

Updated

2025-01-30

·

CVE-2024-8405

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions: PaperCut NG/MF versions with Web Print enabled
Description: The issue is related to an arbitrary file creation vulnerability in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. This vulnerability exists within the web-print.exe process and can be exploited by providing a maliciously formed payload, allowing an attacker to create files that don't exist. This can lead to a Denial of Service (DoS) attack by flooding disk space.
Recommendations: For PaperCut NG/MF versions with Web Print enabled, consider disabling the Web Print feature until a patch is available to prevent exploitation of the arbitrary file creation vulnerability. As a temporary workaround, restrict access to the web-print.exe process to minimize the risk of a Denial of Service (DoS) attack. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-07918
CVE-2024-8405
ZDI-24-1314

Affected Products

Papercut Ng/Mf