{"resultsPerPage":40,"startIndex":0,"totalResults":40,"format":"NVD_CVE","version":"2.0","timestamp":"2026-10-11T00:35:03.836","vulnerabilities":[{"cve":{"id":"CVE-2014-2659","sourceIdentifier":"cve@mitre.org","published":"2014-04-22T14:23:35.910","lastModified":"2026-06-17T00:06:59.573","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-site request forgery (CSRF) vulnerability in the admin UI in Papercut MF and NG before 14.1 (Build 26983) allows remote attackers to hijack the authentication of administrators via unspecified vectors."},{"lang":"es","value":"Vulnerabilidad de CSRF en la interfaz de usuario de administración en Papercut MF y NG anterior a 14.1 (Build 26983) permite a atacantes remotos secuestrar la autenticación de administradores a través de vectores no especificados."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionEndIncluding":"14.1","matchCriteriaId":"C39F2093-2205-4065-930D-433B45C6F868"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:12.0:*:*:*:*:*:*:*","matchCriteriaId":"FF398E65-476C-41C5-9C96-243740F1B429"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:12.1:*:*:*:*:*:*:*","matchCriteriaId":"322A6E60-374D-437D-9F7F-C0DE19894279"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:12.2:*:*:*:*:*:*:*","matchCriteriaId":"DECB5F11-6E2B-42B6-8964-83EA876BF735"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:12.3:*:*:*:*:*:*:*","matchCriteriaId":"4A31AA18-E4C0-4173-9461-2A51723C001C"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:12.4:*:*:*:*:*:*:*","matchCriteriaId":"22BBE05F-26E5-417D-8841-9A2E47D040CA"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:12.5:*:*:*:*:*:*:*","matchCriteriaId":"D14BAE3F-FA54-4495-BE0C-913CC76E4B63"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:13.0:*:*:*:*:*:*:*","matchCriteriaId":"D05483BC-AF45-4A20-93F1-7B9CA6ED104D"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:13.1:*:*:*:*:*:*:*","matchCriteriaId":"661D8595-B0C2-4B81-A921-18031B681B4C"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:13.2:*:*:*:*:*:*:*","matchCriteriaId":"851320F4-8239-482C-A164-1372D7C6AAD9"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:13.3:*:*:*:*:*:*:*","matchCriteriaId":"1429B0AE-F0BB-4770-B8AB-26CA0BBD9975"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:13.4:*:*:*:*:*:*:*","matchCriteriaId":"3A8966A5-3C9E-42DB-92A9-74975E6957FF"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:13.5:*:*:*:*:*:*:*","matchCriteriaId":"B2F6E5F3-FDED-47C6-91D4-6FC6317E4DFA"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:14.0:*:*:*:*:*:*:*","matchCriteriaId":"5B3266B2-CBDC-432D-ACBA-FDF293368FB0"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndIncluding":"14.1","matchCriteriaId":"159145D0-A4ED-4F74-9A1F-6BBB2CC7568A"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:12.0:*:*:*:*:*:*:*","matchCriteriaId":"43F90D1A-6523-4EA2-BD70-3230E01A66E7"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:12.1:*:*:*:*:*:*:*","matchCriteriaId":"DD91C180-D7F1-43BE-8472-5E72DF27993E"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:12.2:*:*:*:*:*:*:*","matchCriteriaId":"C2464601-F136-410A-862F-2273B1782AC6"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:12.3:*:*:*:*:*:*:*","matchCriteriaId":"419FEFF8-A892-403C-BF8A-304272EE16D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:12.4:*:*:*:*:*:*:*","matchCriteriaId":"D02D413C-693E-45B9-83A4-CBFA844FEBB5"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:12.5:*:*:*:*:*:*:*","matchCriteriaId":"5C8A222F-CEEF-481A-BE3C-0D736CE64A18"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:13.0:*:*:*:*:*:*:*","matchCriteriaId":"8B6C4B24-3F7E-48C8-9FE6-5DBFEB4425A6"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:13.1:*:*:*:*:*:*:*","matchCriteriaId":"10E34435-E2C8-417A-9950-FECD267DEA27"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:13.2:*:*:*:*:*:*:*","matchCriteriaId":"30875001-1705-4B52-8DC2-6898DAE23BBC"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:13.3:*:*:*:*:*:*:*","matchCriteriaId":"B66EF4D7-6BBE-4A71-A887-59105AFBEE6D"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:13.4:*:*:*:*:*:*:*","matchCriteriaId":"2620A163-36DD-4D89-8044-893B1A4E823B"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:13.5:*:*:*:*:*:*:*","matchCriteriaId":"00A6BA83-BF06-4E4A-A474-0AB98C55F3D4"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:14.0:*:*:*:*:*:*:*","matchCriteriaId":"7D9025F2-7C5C-4FC9-A239-584215618239"}]}]}],"references":[{"url":"http://secunia.com/advisories/58037","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"http://www.papercut-mf.com/release-history/","source":"cve@mitre.org"},{"url":"http://www.papercut.com/release-history/","source":"cve@mitre.org"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/92648","source":"cve@mitre.org"},{"url":"http://secunia.com/advisories/58037","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://www.papercut-mf.com/release-history/","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.papercut.com/release-history/","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/92648","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2014-2657","sourceIdentifier":"cve@mitre.org","published":"2014-04-28T14:09:07.080","lastModified":"2026-06-17T00:06:59.353","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Unspecified vulnerability in the print release functionality in PaperCut MF before 14.1 (Build 26983) has unknown impact and remote vectors, related to embedded MFPs."},{"lang":"es","value":"Una vulnerabilidad no especificada en la funcionalidad print release en PaperCut MF anterior a la versión 14.1 (Build 26983), presenta un impacto no especificado y vectores remotos, relacionados con MFPs integrados."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:14.1:*:*:*:*:*:*:*","matchCriteriaId":"4457DA19-52CD-4F2E-9053-BF92136E6071"}]}]}],"references":[{"url":"http://www.papercut-mf.com/release-history/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/92650","source":"cve@mitre.org"},{"url":"http://www.papercut-mf.com/release-history/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/92650","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2014-2658","sourceIdentifier":"cve@mitre.org","published":"2014-04-28T14:09:07.517","lastModified":"2026-06-17T00:06:59.460","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Unspecified vulnerability in Papercut MF and NG before 14.1 (Build 26983) allows attacker to cause a denial of service via unknown vectors."},{"lang":"es","value":"Vulnerabilidad no especificada en Papercut MF y NG anterior a 14.1 (Build 26983) permite a atacantes causar una denegación de servicio a través de vectores desconocidos."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionEndIncluding":"14.1","matchCriteriaId":"C39F2093-2205-4065-930D-433B45C6F868"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:12.0:*:*:*:*:*:*:*","matchCriteriaId":"FF398E65-476C-41C5-9C96-243740F1B429"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:12.1:*:*:*:*:*:*:*","matchCriteriaId":"322A6E60-374D-437D-9F7F-C0DE19894279"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:12.2:*:*:*:*:*:*:*","matchCriteriaId":"DECB5F11-6E2B-42B6-8964-83EA876BF735"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:12.3:*:*:*:*:*:*:*","matchCriteriaId":"4A31AA18-E4C0-4173-9461-2A51723C001C"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:12.4:*:*:*:*:*:*:*","matchCriteriaId":"22BBE05F-26E5-417D-8841-9A2E47D040CA"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:12.5:*:*:*:*:*:*:*","matchCriteriaId":"D14BAE3F-FA54-4495-BE0C-913CC76E4B63"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:13.0:*:*:*:*:*:*:*","matchCriteriaId":"D05483BC-AF45-4A20-93F1-7B9CA6ED104D"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:13.1:*:*:*:*:*:*:*","matchCriteriaId":"661D8595-B0C2-4B81-A921-18031B681B4C"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:13.2:*:*:*:*:*:*:*","matchCriteriaId":"851320F4-8239-482C-A164-1372D7C6AAD9"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:13.3:*:*:*:*:*:*:*","matchCriteriaId":"1429B0AE-F0BB-4770-B8AB-26CA0BBD9975"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:13.4:*:*:*:*:*:*:*","matchCriteriaId":"3A8966A5-3C9E-42DB-92A9-74975E6957FF"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:13.5:*:*:*:*:*:*:*","matchCriteriaId":"B2F6E5F3-FDED-47C6-91D4-6FC6317E4DFA"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:14.0:*:*:*:*:*:*:*","matchCriteriaId":"5B3266B2-CBDC-432D-ACBA-FDF293368FB0"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndIncluding":"14.1","matchCriteriaId":"159145D0-A4ED-4F74-9A1F-6BBB2CC7568A"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:12.0:*:*:*:*:*:*:*","matchCriteriaId":"43F90D1A-6523-4EA2-BD70-3230E01A66E7"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:12.1:*:*:*:*:*:*:*","matchCriteriaId":"DD91C180-D7F1-43BE-8472-5E72DF27993E"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:12.2:*:*:*:*:*:*:*","matchCriteriaId":"C2464601-F136-410A-862F-2273B1782AC6"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:12.3:*:*:*:*:*:*:*","matchCriteriaId":"419FEFF8-A892-403C-BF8A-304272EE16D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:12.4:*:*:*:*:*:*:*","matchCriteriaId":"D02D413C-693E-45B9-83A4-CBFA844FEBB5"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:12.5:*:*:*:*:*:*:*","matchCriteriaId":"5C8A222F-CEEF-481A-BE3C-0D736CE64A18"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:13.0:*:*:*:*:*:*:*","matchCriteriaId":"8B6C4B24-3F7E-48C8-9FE6-5DBFEB4425A6"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:13.1:*:*:*:*:*:*:*","matchCriteriaId":"10E34435-E2C8-417A-9950-FECD267DEA27"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:13.2:*:*:*:*:*:*:*","matchCriteriaId":"30875001-1705-4B52-8DC2-6898DAE23BBC"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:13.3:*:*:*:*:*:*:*","matchCriteriaId":"B66EF4D7-6BBE-4A71-A887-59105AFBEE6D"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:13.4:*:*:*:*:*:*:*","matchCriteriaId":"2620A163-36DD-4D89-8044-893B1A4E823B"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:13.5:*:*:*:*:*:*:*","matchCriteriaId":"00A6BA83-BF06-4E4A-A474-0AB98C55F3D4"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:14.0:*:*:*:*:*:*:*","matchCriteriaId":"7D9025F2-7C5C-4FC9-A239-584215618239"}]}]}],"references":[{"url":"http://secunia.com/advisories/58037","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"http://www.papercut-mf.com/release-history/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"http://www.papercut.com/release-history/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/92649","source":"cve@mitre.org"},{"url":"http://secunia.com/advisories/58037","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://www.papercut-mf.com/release-history/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://www.papercut.com/release-history/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/92649","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2019-8948","sourceIdentifier":"cve@mitre.org","published":"2019-02-20T04:29:00.297","lastModified":"2026-06-17T02:42:50.147","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163."},{"lang":"es","value":"PaperCut MF, en versiones anteriores a la 18.3.6, y PaperCut NG, en versiones anteriores a la 18.3.6, permiten la inyección de scripts mediante la interfaz de usuario, también conocida como PC-15163."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-74"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionEndExcluding":"18.3.6","matchCriteriaId":"BEE939C2-CC56-460B-B6B0-DAEF4E77F4DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndExcluding":"18.3.6","matchCriteriaId":"CE4ED3A9-9771-4AB3-8F82-74B0BCA485D5"}]}]}],"references":[{"url":"https://www.papercut.com/products/mf/release-history/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://www.papercut.com/products/ng/release-history/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://www.papercut.com/products/mf/release-history/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://www.papercut.com/products/ng/release-history/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2019-12135","sourceIdentifier":"cve@mitre.org","published":"2019-06-06T17:29:00.307","lastModified":"2026-06-17T02:14:07.627","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An unspecified vulnerability in the application server in PaperCut MF and NG versions 18.3.8 and earlier and versions 19.0.3 and earlier allows remote attackers to execute arbitrary code via an unspecified vector."},{"lang":"es","value":"Una vulnerabilidad sin especificar en la aplicación  server in PaperCut MF y NG versiones 18.3.8  y versiones anteriores 19.0.3 y anteriores, permiten que un atacante remoto ejecute códigos arbitrarios mediante un vector sin especificar."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionEndIncluding":"18.3.8","matchCriteriaId":"9538D248-2BB2-4FE4-B11A-7C97962EEA53"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"19.0.1","versionEndIncluding":"19.0.3","matchCriteriaId":"D14123DF-D87E-49F7-A600-88B2DF8DD573"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndIncluding":"18.3.8","matchCriteriaId":"3D935038-CDB9-4D1B-AD74-67237CCE2C57"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"19.0.1","versionEndIncluding":"19.0.3","matchCriteriaId":"35C8CC9F-6D73-4923-83BC-CCE0383228C7"}]}]}],"references":[{"url":"https://www.papercut.com/products/mf/release-history/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://www.papercut.com/products/ng/release-history/","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://www.papercut.com/products/mf/release-history/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://www.papercut.com/products/ng/release-history/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2023-27350","sourceIdentifier":"zdi-disclosures@trendmicro.com","published":"2023-04-20T16:15:07.653","lastModified":"2026-06-17T05:44:50.950","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987."}],"affected":[{"source":"zdi-disclosures@trendmicro.com","affectedData":[{"vendor":"PaperCut","product":"NG","versions":[{"version":"22.0.5 (Build 63914)","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV30":[{"source":"zdi-disclosures@trendmicro.com","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2023-12-22T05:01:04.658436Z","id":"CVE-2023-27350","options":[{"exploitation":"active"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2023-04-21","cisaActionDue":"2023-05-12","cisaRequiredAction":"Apply updates per vendor instructions.","cisaVulnerabilityName":"PaperCut MF/NG Improper Access Control Vulnerability","weaknesses":[{"source":"zdi-disclosures@trendmicro.com","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"8.0","versionEndExcluding":"20.1.7","matchCriteriaId":"E225189C-FF05-402B-A8F6-6BCC8D062B8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"21.0.0","versionEndExcluding":"21.2.11","matchCriteriaId":"7D231C34-F58C-4CA1-B158-64778AC17991"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"22.0.0","versionEndExcluding":"22.0.9","matchCriteriaId":"A326E88D-635E-4AC1-B5CE-455306FC9D55"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"8.0","versionEndExcluding":"20.1.7","matchCriteriaId":"7F5D942B-C055-4221-8FD7-3F0F252931E4"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"21.0.0","versionEndExcluding":"21.2.11","matchCriteriaId":"4DE19845-02F0-4BB9-BECB-49B34FACB55D"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"22.0.0","versionEndExcluding":"22.0.9","matchCriteriaId":"C1852E7B-0B3F-4208-A26E-CB117E0C0CD8"}]}]}],"references":[{"url":"http://packetstormsecurity.com/files/171982/PaperCut-MF-NG-Authentication-Bypass-Remote-Code-Execution.html","source":"zdi-disclosures@trendmicro.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://packetstormsecurity.com/files/172022/PaperCut-NG-MG-22.0.4-Authentication-Bypass.html","source":"zdi-disclosures@trendmicro.com","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"http://packetstormsecurity.com/files/172512/PaperCut-NG-MG-22.0.4-Remote-Code-Execution.html","source":"zdi-disclosures@trendmicro.com","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"http://packetstormsecurity.com/files/172780/PaperCut-PaperCutNG-Authentication-Bypass.html","source":"zdi-disclosures@trendmicro.com","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"https://news.sophos.com/en-us/2023/04/27/increased-exploitation-of-papercut-drawing-blood-around-the-internet/","source":"zdi-disclosures@trendmicro.com","tags":["Third Party Advisory"]},{"url":"https://www.papercut.com/kb/Main/PO-1216-and-PO-1219","source":"zdi-disclosures@trendmicro.com","tags":["Vendor Advisory"]},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-23-233/","source":"zdi-disclosures@trendmicro.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://packetstormsecurity.com/files/171982/PaperCut-MF-NG-Authentication-Bypass-Remote-Code-Execution.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://packetstormsecurity.com/files/172022/PaperCut-NG-MG-22.0.4-Authentication-Bypass.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"http://packetstormsecurity.com/files/172512/PaperCut-NG-MG-22.0.4-Remote-Code-Execution.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"http://packetstormsecurity.com/files/172780/PaperCut-PaperCutNG-Authentication-Bypass.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"https://news.sophos.com/en-us/2023/04/27/increased-exploitation-of-papercut-drawing-blood-around-the-internet/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.papercut.com/kb/Main/PO-1216-and-PO-1219","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-23-233/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-27350","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}},{"cve":{"id":"CVE-2023-27351","sourceIdentifier":"zdi-disclosures@trendmicro.com","published":"2023-04-20T16:15:07.723","lastModified":"2026-10-01T19:17:14.823","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results from improper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-19226."}],"affected":[{"source":"zdi-disclosures@trendmicro.com","affectedData":[{"vendor":"PaperCut","product":"NG","versions":[{"version":"22.0.5 (Build 63914)","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV30":[{"source":"zdi-disclosures@trendmicro.com","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-21T03:55:38.095423Z","id":"CVE-2023-27351","options":[{"exploitation":"active"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2026-04-20","cisaActionDue":"2026-05-04","cisaRequiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cisaVulnerabilityName":"PaperCut NG/MF Improper Authentication Vulnerability","weaknesses":[{"source":"zdi-disclosures@trendmicro.com","type":"Secondary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"15.0","versionEndExcluding":"20.1.7","matchCriteriaId":"B754BD95-F7CC-4A77-A5FB-B627E1E636DB"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"21.0.0","versionEndExcluding":"21.2.11","matchCriteriaId":"7D231C34-F58C-4CA1-B158-64778AC17991"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"22.0.0","versionEndExcluding":"22.0.9","matchCriteriaId":"A326E88D-635E-4AC1-B5CE-455306FC9D55"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"15.0","versionEndExcluding":"20.1.7","matchCriteriaId":"BFB91DE7-FAEA-4F7D-B4B6-6B5211DE4AD0"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"21.0.0","versionEndExcluding":"21.2.11","matchCriteriaId":"4DE19845-02F0-4BB9-BECB-49B34FACB55D"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"22.0.0","versionEndExcluding":"22.0.9","matchCriteriaId":"C1852E7B-0B3F-4208-A26E-CB117E0C0CD8"}]}]}],"references":[{"url":"https://www.papercut.com/kb/Main/PO-1216-and-PO-1219","source":"zdi-disclosures@trendmicro.com","tags":["Vendor Advisory"]},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-23-232/","source":"zdi-disclosures@trendmicro.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://www.papercut.com/kb/Main/PO-1216-and-PO-1219","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-23-232/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-27351","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}},{"cve":{"id":"CVE-2023-2533","sourceIdentifier":"help@fluidattacks.com","published":"2023-06-20T15:15:11.560","lastModified":"2026-06-17T05:52:47.993","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A Cross-Site Request Forgery (CSRF) vulnerability has been identified in\nPaperCut NG/MF, which, under specific conditions, could potentially enable\nan attacker to alter security settings or execute arbitrary code. This could\nbe exploited if the target is an admin with a current login session. Exploiting\nthis would typically involve the possibility of deceiving an admin into clicking\na specially crafted malicious link, potentially leading to unauthorized changes."},{"lang":"es","value":"Se ha identificado una vulnerabilidad de Cross-Site Request Forgery (CSRF) en PaperCut NG/MF que, en determinadas circunstancias, podría permitir a un atacante alterar la configuración de seguridad o ejecutar código arbitrario. Esto podría explotarse si el objetivo es un administrador con una sesión iniciada. Explotar esto normalmente implicaría la posibilidad de engañar a un administrador para que haga clic en un enlace malicioso especialmente manipulado, lo que podría provocar cambios no autorizados."}],"affected":[{"source":"help@fluidattacks.com","affectedData":[{"vendor":"PaperCut","product":"PaperCut NG/MF","defaultStatus":"unaffected","platforms":["Windows","Linux","MacOS"],"versions":[{"version":"22.0.10","lessThan":"2.1.1","versionType":"custom","status":"affected"},{"version":"21.2.12","status":"unaffected"},{"version":"20.1.8","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"help@fluidattacks.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.7,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-07-26T03:55:53.487003Z","id":"CVE-2023-2533","options":[{"exploitation":"active"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2025-07-28","cisaActionDue":"2025-08-18","cisaRequiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cisaVulnerabilityName":"PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability","weaknesses":[{"source":"help@fluidattacks.com","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionEndExcluding":"20.1.8","matchCriteriaId":"C32F194D-D229-4694-B8AD-94BB7B427378"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"21.0.0","versionEndExcluding":"21.2.12","matchCriteriaId":"373E06E9-6AAB-45D4-84FE-B12BB48086D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"22.0.0","versionEndExcluding":"22.1.1","matchCriteriaId":"B94F9EC5-EC1D-47CB-ABDA-90845C4485AA"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndExcluding":"20.1.8","matchCriteriaId":"E79D1429-D66B-4A09-8375-B92D667D54A3"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"21.0.0","versionEndExcluding":"21.2.12","matchCriteriaId":"BBE00F06-73FB-4A8D-8C34-54517A08CA7A"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"22.0.0","versionEndIncluding":"22.1.1","matchCriteriaId":"BF6B8BA0-F12A-4CD7-8B99-58F7B32ED08E"}]}]}],"references":[{"url":"https://fluidattacks.com/advisories/arcangel/","source":"help@fluidattacks.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.papercut.com/kb/Main/SecurityBulletinJune2023","source":"help@fluidattacks.com","tags":["Vendor Advisory"]},{"url":"https://fluidattacks.com/advisories/arcangel/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.papercut.com/kb/Main/SecurityBulletinJune2023","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-2533","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}},{"cve":{"id":"CVE-2023-3486","sourceIdentifier":"vulnreport@tenable.com","published":"2023-07-25T13:15:10.330","lastModified":"2026-06-17T06:14:11.847","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated attacker to upload arbitrary files to the PaperCut NG host’s file storage. This could exhaust system resources and prevent the service from operating as expected.\n"},{"lang":"es","value":"Existe una omisión de autenticación en las versiones 22.0.12 y anteriores de PaperCut NG que podría permitir a un atacante no remoto no autenticado cargar archivos arbitrarios en el almacenamiento del host de PaperCut NG. Esto podría agotar los recursos del sistema e impedir que el servicio funcione como se espera. "}],"affected":[{"source":"vulnreport@tenable.com","affectedData":[{"vendor":"PaperCut","product":"PaperCut NG","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"22.1.3","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"vulnreport@tenable.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-10-23T19:02:44.379787Z","id":"CVE-2023-3486","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"vulnreport@tenable.com","type":"Secondary","description":[{"lang":"en","value":"CWE-434"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-434"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionEndExcluding":"22.1.3","matchCriteriaId":"2D1E7B69-F906-49B6-A5AE-BC95E528AB81"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndExcluding":"22.1.3","matchCriteriaId":"AE9EEC66-6455-4B4E-879D-7109E6E16199"}]}]}],"references":[{"url":"https://www.papercut.com/kb/Main/SecurityBulletinJuly2023/","source":"vulnreport@tenable.com","tags":["Vendor Advisory"]},{"url":"https://www.tenable.com/security/research/tra-2023-23","source":"vulnreport@tenable.com","tags":["Third Party Advisory"]},{"url":"https://www.papercut.com/kb/Main/SecurityBulletinJuly2023/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://www.tenable.com/security/research/tra-2023-23","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-39143","sourceIdentifier":"cve@mitre.org","published":"2023-08-04T17:15:11.510","lastModified":"2026-06-17T06:11:37.693","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration)."},{"lang":"es","value":"PaperCut NG y PaperCut MF antes de 22.1.3 en Windows permiten atravesar rutas, lo que permite a los atacantes cargar, leer o eliminar archivos arbitrarios. Esto conduce a la ejecución remota de código cuando la integración de dispositivos externos está habilitada (una configuración muy común).\n"}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-23T13:31:30.880621Z","id":"CVE-2023-39143","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionEndExcluding":"22.1.3","matchCriteriaId":"2D1E7B69-F906-49B6-A5AE-BC95E528AB81"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndExcluding":"22.1.3","matchCriteriaId":"AE9EEC66-6455-4B4E-879D-7109E6E16199"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://www.horizon3.ai/cve-2023-39143-papercut-path-traversal-file-upload-rce-vulnerability/","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.papercut.com/kb/Main/securitybulletinjuly2023/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://www.horizon3.ai/cve-2023-39143-papercut-path-traversal-file-upload-rce-vulnerability/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.papercut.com/kb/Main/securitybulletinjuly2023/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2023-4568","sourceIdentifier":"vulnreport@tenable.com","published":"2023-09-13T21:15:07.807","lastModified":"2026-06-17T06:38:07.080","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"PaperCut NG allows for unauthenticated XMLRPC commands to be run by default. Versions 22.0.12 and below are confirmed to be affected, but later versions may also be affected due to lack of a vendor supplied patch."},{"lang":"es","value":"PaperCut NG permite ejecutar comandos XMLRPC no autenticados de forma predeterminada. Se confirma que las versiones 22.0.12 e inferiores están afectadas, pero las versiones posteriores también pueden verse afectadas debido a la falta de un parche proporcionado por el proveedor."}],"affected":[{"source":"vulnreport@tenable.com","affectedData":[{"vendor":"PaperCut","product":"PaperCut NG","defaultStatus":"unaffected","versions":[{"version":"0","status":"unknown"}]}]}],"metrics":{"cvssMetricV31":[{"source":"vulnreport@tenable.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-25T19:57:57.034722Z","id":"CVE-2023-4568","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"vulnreport@tenable.com","type":"Secondary","description":[{"lang":"en","value":"CWE-287"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndIncluding":"22.0.12","matchCriteriaId":"F745BB14-82EB-4539-BECB-0A96C4C60E99"}]}]}],"references":[{"url":"https://www.tenable.com/security/research/tra-2023-31","source":"vulnreport@tenable.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.tenable.com/security/research/tra-2023-31","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-31046","sourceIdentifier":"cve@mitre.org","published":"2023-10-19T14:15:08.883","lastModified":"2026-06-17T05:56:10.547","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A Path Traversal vulnerability exists in PaperCut NG before 22.1.1 and PaperCut MF before 22.1.1. Under specific conditions, this could potentially allow an authenticated attacker to achieve read-only access to the server's filesystem, because requests beginning with \"GET /ui/static/..//..\" reach getStaticContent in UIContentResource.class in the static-content-files servlet."},{"lang":"es","value":"Existe una vulnerabilidad de Path Traversal en PaperCut NG anterior a 22.1.1 y PaperCut MF anterior a 22.1.1. En condiciones específicas, esto podría permitir que un atacante autenticado obtenga acceso de solo lectura al sistema de archivos del servidor, porque las solicitudes que comienzan con \"GET /ui/static/..//..\" alcanza getStaticContent en UIContentResource.class en el servlet static-content-files."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-13T14:48:16.443381Z","id":"CVE-2023-31046","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionEndExcluding":"22.1.1","matchCriteriaId":"E017C8AB-3DE6-4506-8F25-95DCD901FFAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndExcluding":"22.1.1","matchCriteriaId":"3FB63050-D74D-417B-9639-B81D3B789EE1"}]}]}],"references":[{"url":"https://research.aurainfosec.io/disclosure/papercut/","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://web.archive.org/web/20230814061444/https://research.aurainfosec.io/disclosure/papercut/","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://www.papercut.com/kb/Main/PO-1216-and-PO-1219#security-notifications","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://www.papercut.com/kb/Main/SecurityBulletinJune2023","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://research.aurainfosec.io/disclosure/papercut/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://web.archive.org/web/20230814061444/https://research.aurainfosec.io/disclosure/papercut/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.papercut.com/kb/Main/PO-1216-and-PO-1219#security-notifications","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://www.papercut.com/kb/Main/SecurityBulletinJune2023","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2023-6006","sourceIdentifier":"eb41dac7-0af8-4f84-9f6d-0272772514f4","published":"2023-11-14T04:15:07.850","lastModified":"2026-06-17T06:49:50.357","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"This vulnerability potentially allows local attackers to escalate privileges on affected installations of PaperCut NG. An attacker must have local write access to the C Drive. In addition, Print Archiving must be enabled or the attacker needs to encounter a misconfigured system. This vulnerability does not apply to PaperCut NG installs that have Print Archiving enabled and configured as per the recommended set up procedure. This specific flaw exists within the pc-pdl-to-image process. The process loads an executable from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM\n\nNote: This CVE has been rescored with a \"Privileges Required (PR)\" rating of low, and “Attack Complexity (AC)” rating of low, reflecting the worst-case scenario where an Administrator has granted local login access to standard network users on the host server."},{"lang":"es","value":"Esta vulnerabilidad permite a atacantes locales escalar privilegios en las instalaciones afectadas de PaperCut NG. Un atacante primero debe obtener la capacidad de ejecutar código con pocos privilegios en el sistema de destino para poder aprovechar esta vulnerabilidad. La falla específica existe dentro del proceso pc-pdl-to-image. El proceso carga un ejecutable desde una ubicación no segura. Un atacante puede aprovechar esta vulnerabilidad para escalar privilegios y ejecutar código arbitrario en el contexto de SYSTEM."}],"affected":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","affectedData":[{"vendor":"PaperCut","product":"PaperCut NG, PaperCut MF","defaultStatus":"unaffected","modules":["Print Archiving"],"platforms":["Windows"],"versions":[{"version":"0","lessThan":"23.0.0","versionType":"custom","status":"affected","changes":[{"at":"23.0.0","status":"unaffected"}]}]}]}],"metrics":{"cvssMetricV31":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-01-30T18:23:10.697416Z","id":"CVE-2023-6006","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","description":[{"lang":"en","value":"CWE-250"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionEndExcluding":"23.0.1","matchCriteriaId":"C90A3C1C-5F05-4FA3-89D6-8A6D0A17664B"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndExcluding":"23.0.1","matchCriteriaId":"D754F687-4EFB-4B04-96CE-C78C30B527FB"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://www.papercut.com/kb/Main/Security-Bulletin-November-2023/","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","tags":["Vendor Advisory"]},{"url":"https://www.papercut.com/kb/Main/CommonSecurityQuestions/","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.papercut.com/kb/Main/Security-Bulletin-November-2023/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2024-1221","sourceIdentifier":"eb41dac7-0af8-4f84-9f6d-0272772514f4","published":"2024-03-14T03:15:06.607","lastModified":"2026-06-17T07:03:44.760","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"This vulnerability potentially allows files on a PaperCut NG/MF server to be exposed using a specifically formed payload against the impacted API endpoint. The attacker must carry out some reconnaissance to gain knowledge of a system token. This CVE only affects Linux and macOS PaperCut NG/MF servers."},{"lang":"es","value":"Esta vulnerabilidad potencialmente permite que los archivos en un servidor PaperCut NG/MF queden expuestos utilizando un payload formado específicamente contra el endpoint API afectado. El atacante debe realizar algún reconocimiento para conocer un token del sistema. Este CVE solo afecta a los servidores PaperCut NG/MF de Linux y macOS."}],"affected":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","affectedData":[{"vendor":"PaperCut","product":"PaperCut NG, PaperCut MF","defaultStatus":"affected","platforms":["MacOS","Linux"],"versions":[{"version":"0","lessThan":"23.0.7","versionType":"custom","status":"affected","changes":[{"at":"23.0.7","status":"unaffected"}]},{"version":"0","lessThan":"22.1.5","versionType":"custom","status":"affected","changes":[{"at":"22.1.5","status":"unaffected"}]},{"version":"0","lessThan":"21.2.14","versionType":"custom","status":"affected","changes":[{"at":"21.2.14","status":"unaffected"}]},{"version":"0","lessThan":"20.1.10","versionType":"custom","status":"affected","changes":[{"at":"20.1.10","status":"unaffected"}]}]}]}],"metrics":{"cvssMetricV31":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-03-15T15:25:34.441612Z","id":"CVE-2024-1221","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","description":[{"lang":"en","value":"CWE-76"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionEndExcluding":"20.1.10","matchCriteriaId":"87E57A99-6580-4C5D-AD49-2C77153698B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"21.0.0","versionEndExcluding":"21.2.14","matchCriteriaId":"AC862C5A-C51D-455A-BA4C-62AF4B5593D6"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"22.0.0","versionEndExcluding":"22.1.5","matchCriteriaId":"3B444455-3DE9-4268-AED3-9457016B833F"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"23.0.1","versionEndExcluding":"23.0.7","matchCriteriaId":"06311316-1937-41A4-BEE2-57F7C4F6B6BC"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndExcluding":"20.1.10","matchCriteriaId":"F7A1BAB4-D3AC-4A06-B2AB-E46DED8CB19D"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"21.0.0","versionEndExcluding":"21.2.14","matchCriteriaId":"570DCFBC-7689-4E77-A8BF-8F310545EDE3"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"22.0.0","versionEndExcluding":"22.1.5","matchCriteriaId":"728ECAA8-FE3E-4F6D-8862-AF0C100C6699"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"23.0.1","versionEndExcluding":"23.0.7","matchCriteriaId":"7155AC1E-E4C8-4EF5-B593-7C924AF0C625"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*","matchCriteriaId":"387021A0-AF36-463C-A605-32EA7DAC172E"},{"vulnerable":false,"criteria":"cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*","matchCriteriaId":"703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"}]}]}],"references":[{"url":"https://www.papercut.com/kb/Main/Security-Bulletin-March-2024","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","tags":["Vendor Advisory"]},{"url":"https://www.papercut.com/kb/Main/Security-Bulletin-March-2024","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2024-1222","sourceIdentifier":"eb41dac7-0af8-4f84-9f6d-0272772514f4","published":"2024-03-14T03:15:07.090","lastModified":"2026-06-17T07:03:44.900","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This applies to a small subset of PaperCut NG/MF API calls."},{"lang":"es","value":"Esto permite a los atacantes utilizar una solicitud de API formada de forma maliciosa para obtener acceso a un nivel de autorización de API con privilegios elevados. Esto se aplica a un pequeño subconjunto de llamadas API de PaperCut NG/MF."}],"affected":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","affectedData":[{"vendor":"PaperCut","product":"PaperCut NG, PaperCut MF","defaultStatus":"affected","platforms":["MacOS","Linux","Windows"],"versions":[{"version":"0","lessThan":"23.0.7","versionType":"custom","status":"affected","changes":[{"at":"23.0.7","status":"unaffected"}]},{"version":"0","lessThan":"22.1.5","versionType":"custom","status":"affected","changes":[{"at":"22.1.5","status":"unaffected"}]},{"version":"0","lessThan":"21.2.14","versionType":"custom","status":"affected","changes":[{"at":"21.2.14","status":"unaffected"}]},{"version":"0","lessThan":"20.1.10","versionType":"custom","status":"affected","changes":[{"at":"20.1.10","status":"unaffected"}]}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"papercut","product":"papercut_mf","defaultStatus":"affected","cpes":["cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThan":"23.0.7","versionType":"custom","status":"affected"},{"version":"0","lessThan":"22.1.5","versionType":"custom","status":"affected"},{"version":"0","lessThan":"21.2.14","versionType":"custom","status":"affected"},{"version":"0","lessThan":"20.1.10","versionType":"custom","status":"affected"}]},{"vendor":"papercut","product":"papercut_ng","defaultStatus":"affected","cpes":["cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThan":"23.0.7","versionType":"custom","status":"affected"},{"version":"0","lessThan":"22.1.5","versionType":"custom","status":"affected"},{"version":"0","lessThan":"21.2.14","versionType":"custom","status":"affected"},{"version":"0","lessThan":"20.1.10","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":4.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-03-26T04:00:45.176980Z","id":"CVE-2024-1222","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","description":[{"lang":"en","value":"CWE-250"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionEndExcluding":"20.1.10","matchCriteriaId":"87E57A99-6580-4C5D-AD49-2C77153698B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"21.0.0","versionEndExcluding":"21.2.14","matchCriteriaId":"AC862C5A-C51D-455A-BA4C-62AF4B5593D6"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"22.0.0","versionEndExcluding":"22.1.5","matchCriteriaId":"3B444455-3DE9-4268-AED3-9457016B833F"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"23.0.1","versionEndExcluding":"23.0.7","matchCriteriaId":"06311316-1937-41A4-BEE2-57F7C4F6B6BC"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndExcluding":"20.1.10","matchCriteriaId":"F7A1BAB4-D3AC-4A06-B2AB-E46DED8CB19D"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"21.0.0","versionEndExcluding":"21.2.14","matchCriteriaId":"570DCFBC-7689-4E77-A8BF-8F310545EDE3"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"22.0.0","versionEndExcluding":"22.1.5","matchCriteriaId":"728ECAA8-FE3E-4F6D-8862-AF0C100C6699"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"23.0.1","versionEndExcluding":"23.0.7","matchCriteriaId":"7155AC1E-E4C8-4EF5-B593-7C924AF0C625"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*","matchCriteriaId":"387021A0-AF36-463C-A605-32EA7DAC172E"},{"vulnerable":false,"criteria":"cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*","matchCriteriaId":"703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://www.papercut.com/kb/Main/Security-Bulletin-March-2024","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","tags":["Vendor Advisory"]},{"url":"https://www.papercut.com/kb/Main/Security-Bulletin-March-2024","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2024-1882","sourceIdentifier":"eb41dac7-0af8-4f84-9f6d-0272772514f4","published":"2024-03-14T04:15:08.003","lastModified":"2026-06-17T07:05:12.720","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for remote code execution on the server hosting the PaperCut NG/MF application server."},{"lang":"es","value":"Esta vulnerabilidad permite que un usuario administrador ya autenticado cree un payload malicioso que podría aprovecharse para la ejecución remota de código en el servidor que aloja el servidor de aplicaciones PaperCut NG/MF."}],"affected":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","affectedData":[{"vendor":"PaperCut","product":"PaperCut NG, PaperCut MF","defaultStatus":"affected","platforms":["MacOS","Linux","Windows"],"versions":[{"version":"0","lessThan":"23.0.7","versionType":"custom","status":"affected","changes":[{"at":"23.0.7","status":"unaffected"}]},{"version":"0","lessThan":"22.1.5","versionType":"custom","status":"affected","changes":[{"at":"22.1.5","status":"unaffected"}]},{"version":"0","lessThan":"21.2.14","versionType":"custom","status":"affected","changes":[{"at":"21.2.14","status":"unaffected"}]},{"version":"0","lessThan":"20.1.10","versionType":"custom","status":"affected","changes":[{"at":"20.1.10","status":"unaffected"}]}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"papercut","product":"papercut_ng","defaultStatus":"affected","cpes":["cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThan":"23.0.7","versionType":"custom","status":"affected"},{"version":"0","lessThan":"22.1.5","versionType":"custom","status":"affected"},{"version":"0","lessThan":"21.2.14","versionType":"custom","status":"affected"},{"version":"0","lessThan":"20.1.10","versionType":"custom","status":"affected"}]},{"vendor":"papercut","product":"papercut_mf","defaultStatus":"affected","cpes":["cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThan":"23.0.7","versionType":"custom","status":"affected"},{"version":"0","lessThan":"22.1.5","versionType":"custom","status":"affected"},{"version":"0","lessThan":"21.2.14","versionType":"custom","status":"affected"},{"version":"0","lessThan":"20.1.10","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-03-16T04:00:55.398174Z","id":"CVE-2024-1882","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","description":[{"lang":"en","value":"CWE-76"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionEndExcluding":"20.1.10","matchCriteriaId":"87E57A99-6580-4C5D-AD49-2C77153698B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"21.0.0","versionEndExcluding":"21.2.14","matchCriteriaId":"AC862C5A-C51D-455A-BA4C-62AF4B5593D6"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"22.0.0","versionEndExcluding":"22.1.5","matchCriteriaId":"3B444455-3DE9-4268-AED3-9457016B833F"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"23.0.1","versionEndExcluding":"23.0.7","matchCriteriaId":"06311316-1937-41A4-BEE2-57F7C4F6B6BC"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndExcluding":"20.1.10","matchCriteriaId":"F7A1BAB4-D3AC-4A06-B2AB-E46DED8CB19D"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"21.0.0","versionEndExcluding":"21.2.14","matchCriteriaId":"570DCFBC-7689-4E77-A8BF-8F310545EDE3"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"22.0.0","versionEndExcluding":"22.1.5","matchCriteriaId":"728ECAA8-FE3E-4F6D-8862-AF0C100C6699"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"23.0.1","versionEndExcluding":"23.0.7","matchCriteriaId":"7155AC1E-E4C8-4EF5-B593-7C924AF0C625"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*","matchCriteriaId":"387021A0-AF36-463C-A605-32EA7DAC172E"},{"vulnerable":false,"criteria":"cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*","matchCriteriaId":"703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://www.papercut.com/kb/Main/Security-Bulletin-March-2024","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","tags":["Vendor Advisory"]},{"url":"https://www.papercut.com/kb/Main/Security-Bulletin-March-2024","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2024-1883","sourceIdentifier":"eb41dac7-0af8-4f84-9f6d-0272772514f4","published":"2024-03-14T04:15:08.353","lastModified":"2026-06-17T07:05:12.850","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit this weakness by crafting a malicious URL that contains a script. When an unsuspecting user clicks on this malicious link, it could potentially lead to limited loss of confidentiality, integrity or availability."},{"lang":"es","value":"Esta es una vulnerabilidad de Cross Site Scripting reflejada en el servidor de aplicaciones PaperCut NG/MF. Un atacante puede aprovechar esta debilidad creando una URL maliciosa que contenga un script. Cuando un usuario desprevenido hace clic en este enlace malicioso, podría provocar una pérdida limitada de confidencialidad, integridad o disponibilidad."}],"affected":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","affectedData":[{"vendor":"PaperCut","product":"PaperCut NG, PaperCut MF","defaultStatus":"affected","platforms":["MacOS","Linux","Windows"],"versions":[{"version":"0","lessThan":"23.0.7","versionType":"custom","status":"affected","changes":[{"at":"23.0.7","status":"unaffected"}]},{"version":"0","lessThan":"22.1.5","versionType":"custom","status":"affected","changes":[{"at":"22.1.5","status":"unaffected"}]},{"version":"0","lessThan":"21.2.14","versionType":"custom","status":"affected","changes":[{"at":"21.2.14","status":"unaffected"}]},{"version":"0","lessThan":"20.1.10","versionType":"custom","status":"affected","changes":[{"at":"20.1.10","status":"unaffected"}]}]}]}],"metrics":{"cvssMetricV31":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":3.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-03-15T15:24:48.682883Z","id":"CVE-2024-1883","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","description":[{"lang":"en","value":"CWE-76"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionEndExcluding":"20.1.10","matchCriteriaId":"87E57A99-6580-4C5D-AD49-2C77153698B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"21.0.0","versionEndExcluding":"21.2.14","matchCriteriaId":"AC862C5A-C51D-455A-BA4C-62AF4B5593D6"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"22.0.0","versionEndExcluding":"22.1.5","matchCriteriaId":"3B444455-3DE9-4268-AED3-9457016B833F"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"23.0.1","versionEndExcluding":"23.0.7","matchCriteriaId":"06311316-1937-41A4-BEE2-57F7C4F6B6BC"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndExcluding":"20.1.10","matchCriteriaId":"F7A1BAB4-D3AC-4A06-B2AB-E46DED8CB19D"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"21.0.0","versionEndExcluding":"21.2.14","matchCriteriaId":"570DCFBC-7689-4E77-A8BF-8F310545EDE3"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"22.0.0","versionEndExcluding":"22.1.5","matchCriteriaId":"728ECAA8-FE3E-4F6D-8862-AF0C100C6699"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"23.0.1","versionEndExcluding":"23.0.7","matchCriteriaId":"7155AC1E-E4C8-4EF5-B593-7C924AF0C625"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*","matchCriteriaId":"387021A0-AF36-463C-A605-32EA7DAC172E"},{"vulnerable":false,"criteria":"cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*","matchCriteriaId":"703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://www.papercut.com/kb/Main/Security-Bulletin-March-2024","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","tags":["Vendor Advisory"]},{"url":"https://www.papercut.com/kb/Main/Security-Bulletin-March-2024","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2024-1884","sourceIdentifier":"eb41dac7-0af8-4f84-9f6d-0272772514f4","published":"2024-03-14T04:15:08.697","lastModified":"2026-06-17T07:05:12.983","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that  allows an attacker to induce the server-side application to make HTTP requests to an arbitrary domain of the attacker's choosing."},{"lang":"es","value":"Esta es una vulnerabilidad de Server-Side Request Forgery (SSRF) en PaperCut NG/MF server-side module que permite a un atacante inducir a la aplicación del lado del servidor a realizar solicitudes HTTP a un dominio arbitrario de su elección."}],"affected":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","affectedData":[{"vendor":"PaperCut","product":"PaperCut NG, PaperCut MF","defaultStatus":"affected","platforms":["MacOS","Linux","Windows"],"versions":[{"version":"0","lessThan":"23.0.7","versionType":"custom","status":"affected","changes":[{"at":"23.0.7","status":"unaffected"}]},{"version":"0","lessThan":"22.1.5","versionType":"custom","status":"affected","changes":[{"at":"22.1.5","status":"unaffected"}]},{"version":"0","lessThan":"21.2.14","versionType":"custom","status":"affected","changes":[{"at":"21.2.14","status":"unaffected"}]},{"version":"0","lessThan":"20.1.10","versionType":"custom","status":"affected","changes":[{"at":"20.1.10","status":"unaffected"}]}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"papercut","product":"papercut_ng","defaultStatus":"affected","cpes":["cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThan":"23.0.7","versionType":"custom","status":"affected"},{"version":"0","lessThan":"22.1.5","versionType":"custom","status":"affected"},{"version":"0","lessThan":"21.2.14","versionType":"custom","status":"affected"},{"version":"0","lessThan":"20.1.10","versionType":"custom","status":"affected"}]},{"vendor":"papercut","product":"papercut_mf","defaultStatus":"affected","cpes":["cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThan":"23.0.7","versionType":"custom","status":"affected"},{"version":"0","lessThan":"22.1.5","versionType":"custom","status":"affected"},{"version":"0","lessThan":"21.2.14","versionType":"custom","status":"affected"},{"version":"0","lessThan":"20.1.10","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-03-14T15:43:10.845115Z","id":"CVE-2024-1884","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionEndExcluding":"20.1.10","matchCriteriaId":"87E57A99-6580-4C5D-AD49-2C77153698B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"21.0.0","versionEndExcluding":"21.2.14","matchCriteriaId":"AC862C5A-C51D-455A-BA4C-62AF4B5593D6"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"22.0.0","versionEndExcluding":"22.1.5","matchCriteriaId":"3B444455-3DE9-4268-AED3-9457016B833F"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"23.0.1","versionEndExcluding":"23.0.7","matchCriteriaId":"06311316-1937-41A4-BEE2-57F7C4F6B6BC"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndExcluding":"20.1.10","matchCriteriaId":"F7A1BAB4-D3AC-4A06-B2AB-E46DED8CB19D"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"21.0.0","versionEndExcluding":"21.2.14","matchCriteriaId":"570DCFBC-7689-4E77-A8BF-8F310545EDE3"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"22.0.0","versionEndExcluding":"22.1.5","matchCriteriaId":"728ECAA8-FE3E-4F6D-8862-AF0C100C6699"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"23.0.1","versionEndExcluding":"23.0.7","matchCriteriaId":"7155AC1E-E4C8-4EF5-B593-7C924AF0C625"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*","matchCriteriaId":"387021A0-AF36-463C-A605-32EA7DAC172E"},{"vulnerable":false,"criteria":"cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*","matchCriteriaId":"703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://www.papercut.com/kb/Main/Security-Bulletin-March-2024","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","tags":["Vendor Advisory"]},{"url":"https://www.papercut.com/kb/Main/Security-Bulletin-March-2024","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2023-39469","sourceIdentifier":"zdi-disclosures@trendmicro.com","published":"2024-05-03T03:15:12.730","lastModified":"2026-06-17T06:12:23.930","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"PaperCut NG External User Lookup Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PaperCut NG. Authentication is required to exploit this vulnerability.\n\nThe specific flaw exists within the External User Lookup functionality. The issue results from the lack of proper validation of a user-supplied string before using it to execute Java code. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-21013."},{"lang":"es","value":"Vulnerabilidad de ejecución remota de código de inyección de código de búsqueda de usuario externo de PaperCut NG. Esta vulnerabilidad permite a atacantes remotos ejecutar código arbitrario en instalaciones afectadas de PaperCut NG. Se requiere autenticación para aprovechar esta vulnerabilidad. La falla específica existe dentro de la funcionalidad de búsqueda de usuarios externos. El problema se debe a la falta de validación adecuada de una cadena proporcionada por el usuario antes de usarla para ejecutar código Java. Un atacante puede aprovechar esta vulnerabilidad para ejecutar código en el contexto de SYSTEM. Era ZDI-CAN-21013."}],"affected":[{"source":"zdi-disclosures@trendmicro.com","affectedData":[{"vendor":"PaperCut","product":"NG","defaultStatus":"unknown","versions":[{"version":"22.0.12","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"papercut","product":"papercut_ng","defaultStatus":"unknown","cpes":["cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*"],"versions":[{"version":"22.0.12","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"cvssMetricV30":[{"source":"zdi-disclosures@trendmicro.com","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-05-06T15:38:33.991469Z","id":"CVE-2023-39469","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"zdi-disclosures@trendmicro.com","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-94"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionEndExcluding":"22.1.1","matchCriteriaId":"E017C8AB-3DE6-4506-8F25-95DCD901FFAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndExcluding":"22.1.1","matchCriteriaId":"3FB63050-D74D-417B-9639-B81D3B789EE1"}]}]}],"references":[{"url":"https://www.papercut.com/kb/Main/SecurityBulletinJuly2023/","source":"zdi-disclosures@trendmicro.com","tags":["Vendor Advisory","Related"]},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-23-1285/","source":"zdi-disclosures@trendmicro.com","tags":["Third Party Advisory"]},{"url":"https://www.papercut.com/kb/Main/SecurityBulletinJuly2023/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory","Related"]},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-23-1285/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2024-3037","sourceIdentifier":"eb41dac7-0af8-4f84-9f6d-0272772514f4","published":"2024-05-14T15:39:48.660","lastModified":"2026-06-17T07:43:10.953","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of executing low-privilege code directly on the server. \n\nImportant: In most installations, this risk is mitigated by the default Windows Server configuration, which typically restricts local login access to Administrators only. However, this vulnerability could pose a risk to customers who allow non-administrative users to log in to the local console of the Windows environment hosting the PaperCut NG/MF application server.\n\nNote: This CVE has been split into two separate CVEs (CVE-2024-3037 and CVE-2024-8404) and it’s been rescored with a \"Privileges Required (PR)\" rating of low, and “Attack Complexity (AC)” rating of low, reflecting the worst-case scenario where an Administrator has granted local login access to standard users on the host server."},{"lang":"es","value":"Existe una vulnerabilidad de eliminación arbitraria de archivos en PaperCut NG/MF que solo afecta a los servidores Windows con Web Print habilitado. Esta vulnerabilidad requiere acceso a la consola o inicio de sesión local al servidor PaperCut NG/MF (por ejemplo, miembro de un grupo de administración de dominio)."}],"affected":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","affectedData":[{"vendor":"PaperCut","product":"PaperCut NG, PaperCut MF","defaultStatus":"unaffected","modules":["Web Print"],"platforms":["Windows"],"versions":[{"version":"0","lessThan":"23.0.9","versionType":"custom","status":"affected","changes":[{"at":"23.0.9","status":"unaffected"}]}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"papercut","product":"papercut_ng","defaultStatus":"unaffected","cpes":["cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThan":"23.0.9","versionType":"custom","status":"affected"}]},{"vendor":"papercut","product":"papercut_mf","defaultStatus":"unaffected","cpes":["cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThan":"23.0.9","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-10-07T20:25:16.955265Z","id":"CVE-2024-3037","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","description":[{"lang":"en","value":"CWE-59"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-552"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionEndExcluding":"23.0.9","matchCriteriaId":"7AE8A9B5-11C6-4FE2-B672-0EC6EF8075CC"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndExcluding":"23.0.9","matchCriteriaId":"BA96610E-7518-4215-B5FF-1B4444BE2DA4"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://www.papercut.com/kb/Main/Security-Bulletin-May-2024/","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","tags":["Vendor Advisory"]},{"url":"https://www.papercut.com/kb/Main/security-bulletin-may-2024/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2024-4712","sourceIdentifier":"eb41dac7-0af8-4f84-9f6d-0272772514f4","published":"2024-05-14T15:44:27.660","lastModified":"2026-06-17T08:02:27.880","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This specific flaw exists within the image-handler process, which can incorrectly create files that don’t exist when a maliciously formed payload is provided. This can lead to local privilege escalation.\n\nNote: \n\nThis CVE has been split into two (CVE-2024-4712 and CVE-2024-8405) and it’s been rescored with a \"Privileges Required (PR)\" rating of low, and “Attack Complexity (AC)” rating of low, reflecting the worst-case scenario where an Administrator has granted local login access to standard network users on the host server."},{"lang":"es","value":"Existe una vulnerabilidad de creación de archivos arbitraria en PaperCut NG/MF que solo afecta a los servidores Windows con Web Print habilitado. Esta vulnerabilidad requiere inicio de sesión local/acceso a la consola del servidor PaperCut NG/MF (por ejemplo: miembro de un grupo de administración de dominio)."}],"affected":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","affectedData":[{"vendor":"PaperCut","product":"PaperCut NG, PaperCut MF","defaultStatus":"unaffected","modules":["Web Print"],"platforms":["Windows"],"versions":[{"version":"0","lessThan":"23.0.9","versionType":"custom","status":"affected","changes":[{"at":"23.0.9","status":"unaffected"}]}]}]}],"metrics":{"cvssMetricV31":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-06-20T19:40:02.500241Z","id":"CVE-2024-4712","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","description":[{"lang":"en","value":"CWE-77"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionEndExcluding":"23.0.9","matchCriteriaId":"7AE8A9B5-11C6-4FE2-B672-0EC6EF8075CC"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndExcluding":"23.0.9","matchCriteriaId":"BA96610E-7518-4215-B5FF-1B4444BE2DA4"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://www.papercut.com/kb/Main/Security-Bulletin-May-2024/","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","tags":["Vendor Advisory"]},{"url":"https://www.papercut.com/kb/Main/security-bulletin-may-2024/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2024-8404","sourceIdentifier":"eb41dac7-0af8-4f84-9f6d-0272772514f4","published":"2024-09-26T02:15:02.797","lastModified":"2026-06-17T08:22:31.103","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of executing low-privilege code directly on the server via the web-print-hot-folder. \n\nImportant: In most installations, this risk is mitigated by the default Windows Server configuration, which restricts local login access to Administrators only. However, this vulnerability could pose a risk to customers who allow non-administrative users to log into the local console of the Windows environment hosting the PaperCut NG/MF application server.\n\nUpdate:\n\nThis CVE has been updated in May 2025 to update the fixed version and fix process. Please refer to the May 2025 Security Bulletin.\n\nNote: \n\nThis CVE has been split from CVE-2024-3037."},{"lang":"es","value":"Existe una vulnerabilidad de eliminación arbitraria de archivos en PaperCut NG/MF, que afecta específicamente a servidores Windows con Web Print habilitado. Para explotar esta vulnerabilidad, un atacante primero debe obtener acceso de inicio de sesión local al servidor Windows que aloja PaperCut NG/MF y ser capaz de ejecutar código con privilegios bajos directamente en el servidor a través de la carpeta activa de impresión web. Importante: En la mayoría de las instalaciones, este riesgo se mitiga con la configuración predeterminada de Windows Server, que restringe el acceso de inicio de sesión local solo a los administradores. Sin embargo, esta vulnerabilidad podría representar un riesgo para los clientes que permiten que usuarios no administrativos inicien sesión en la consola local del entorno Windows que aloja el servidor de aplicaciones PaperCut NG/MF. Nota: Esta CVE se ha separado de CVE-2024-3037."}],"affected":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","affectedData":[{"vendor":"PaperCut","product":"PaperCut NG, PaperCut MF","defaultStatus":"unaffected","modules":["Web Print"],"platforms":["Windows"],"versions":[{"version":"0","lessThan":"24.1.7","versionType":"custom","status":"affected","changes":[{"at":"24.1.7","status":"unaffected"}]}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"papercut","product":"papercut_mf","defaultStatus":"unaffected","cpes":["cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThan":"23.0.9","versionType":"custom","status":"affected"}]},{"vendor":"papercut","product":"papercut_ng","defaultStatus":"unaffected","cpes":["cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThan":"23.0.9","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-26T14:59:11.788417Z","id":"CVE-2024-8404","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","description":[{"lang":"en","value":"CWE-59"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-59"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionEndExcluding":"23.0.9","matchCriteriaId":"7AE8A9B5-11C6-4FE2-B672-0EC6EF8075CC"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndExcluding":"23.0.9","matchCriteriaId":"BA96610E-7518-4215-B5FF-1B4444BE2DA4"}]}]}],"references":[{"url":"https://www.papercut.com/kb/Main/Security-Bulletin-May-2024/","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","tags":["Vendor Advisory"]},{"url":"https://www.papercut.com/kb/Main/Security-Bulletin-May-2025/","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4"}]}},{"cve":{"id":"CVE-2024-8405","sourceIdentifier":"eb41dac7-0af8-4f84-9f6d-0272772514f4","published":"2024-09-26T02:15:03.007","lastModified":"2026-06-17T08:22:31.230","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This specific flaw exists within the web-print.exe process, which can incorrectly create files that don’t exist when a maliciously formed payload is provided. This can be used to flood disk space and result in a Denial of Service (DoS) attack.\n\nNote: \n\nThis CVE has been split from CVE-2024-4712."},{"lang":"es","value":"Existe una vulnerabilidad de creación de archivos arbitrarios en PaperCut NG/MF que solo afecta a los servidores Windows con Web Print habilitado. Esta falla específica existe dentro del proceso web-print.exe, que puede crear incorrectamente archivos que no existen cuando se proporciona un payload malicioso. Esto se puede utilizar para inundar el espacio del disco y provocar un ataque de denegación de servicio (DoS). Nota: esta CVE se ha separado de CVE-2024-4712."}],"affected":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","affectedData":[{"vendor":"PaperCut","product":"PaperCut NG, PaperCut MF","defaultStatus":"unaffected","modules":["Web Print"],"platforms":["Windows"],"versions":[{"version":"0","lessThan":"23.0.9","versionType":"custom","status":"affected","changes":[{"at":"23.0.9","status":"unaffected"}]}]}]}],"metrics":{"cvssMetricV31":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-26T15:01:57.724249Z","id":"CVE-2024-8405","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","description":[{"lang":"en","value":"CWE-77"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-77"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionEndExcluding":"23.0.9","matchCriteriaId":"7AE8A9B5-11C6-4FE2-B672-0EC6EF8075CC"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndExcluding":"23.0.9","matchCriteriaId":"BA96610E-7518-4215-B5FF-1B4444BE2DA4"}]}]}],"references":[{"url":"https://www.papercut.com/kb/Main/Security-Bulletin-May-2024/","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2023-39470","sourceIdentifier":"zdi-disclosures@trendmicro.com","published":"2024-11-22T20:15:05.487","lastModified":"2026-06-17T06:12:24.057","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"PaperCut NG print.script.sandboxed Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PaperCut NG. Authentication is required to exploit this vulnerability.\n\nThe specific flaw exists within the management of the print.script.sandboxed setting. The issue results from the exposure of a dangerous function. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-20965."},{"lang":"es","value":"Vulnerabilidad de ejecución remota de código en la función peligrosa print.script.sandboxed de PaperCut NG expuesta. Esta vulnerabilidad permite a atacantes remotos ejecutar código arbitrario en las instalaciones afectadas de PaperCut NG. Se requiere autenticación para explotar esta vulnerabilidad. La falla específica existe dentro de la administración de la configuración print.script.sandboxed. El problema es el resultado de la exposición de una función peligrosa. Un atacante puede aprovechar esta vulnerabilidad para ejecutar código en el contexto de SYSTEM. Era ZDI-CAN-20965."}],"affected":[{"source":"zdi-disclosures@trendmicro.com","affectedData":[{"vendor":"PaperCut","product":"NG","defaultStatus":"unknown","versions":[{"version":"22.0.10 65996","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"papercut","product":"papercut_ng","defaultStatus":"unknown","cpes":["cpe:2.3:a:papercut:papercut_ng:22.0.10:*:*:*:*:*:*:*"],"versions":[{"version":"22.0.10 65996","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"cvssMetricV30":[{"source":"zdi-disclosures@trendmicro.com","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-26T15:16:31.968489Z","id":"CVE-2023-39470","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"zdi-disclosures@trendmicro.com","type":"Secondary","description":[{"lang":"en","value":"CWE-749"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndExcluding":"22.1.1","matchCriteriaId":"3FB63050-D74D-417B-9639-B81D3B789EE1"}]}]}],"references":[{"url":"https://www.papercut.com/kb/Main/SecurityBulletinJune2023/","source":"zdi-disclosures@trendmicro.com","tags":["Vendor Advisory"]},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-24-786/","source":"zdi-disclosures@trendmicro.com","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2024-9672","sourceIdentifier":"eb41dac7-0af8-4f84-9f6d-0272772514f4","published":"2024-12-10T00:15:22.893","lastModified":"2026-06-17T08:25:01.730","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A reflected cross-site scripting (XSS) vulnerability exists in PaperCut NG/MF. This issue can be used to execute specially created JavaScript payloads in the browser. A user must click on a malicious link for this issue to occur."},{"lang":"es","value":"Existe una vulnerabilidad de Cross Site Scripting (XSS) reflejado en PaperCut NG/MF. Este problema se puede aprovechar para ejecutar payloads de JavaScript manipuladas especialmente en el navegador. El usuario debe hacer clic en un enlace malicioso para que se produzca este problema."}],"affected":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","affectedData":[{"vendor":"PaperCut","product":"PaperCut MF","defaultStatus":"unaffected","platforms":["Windows","MacOS","Linux"],"versions":[{"version":"0","lessThan":"24.1","versionType":"custom","status":"affected","changes":[{"at":"24.1","status":"unaffected"}]}]}]}],"metrics":{"cvssMetricV40":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"ACTIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-12-10T16:08:26.031308Z","id":"CVE-2024-9672","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","description":[{"lang":"en","value":"CWE-917"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionEndExcluding":"24.1.1","matchCriteriaId":"E8AE5D47-8CB0-430E-B147-600B3A8ADEE0"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndExcluding":"24.1.1","matchCriteriaId":"93771380-A071-496A-9219-72299310F2F6"}]}]}],"references":[{"url":"https://www.papercut.com/kb/Main/security-bulletin-december-2024/","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-9785","sourceIdentifier":"eb41dac7-0af8-4f84-9f6d-0272772514f4","published":"2025-09-03T05:15:30.910","lastModified":"2026-09-26T00:10:00.127","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"PaperCut Print Deploy is an optional component that integrates with PaperCut NG/MF which simplifies printer deployment and management. When the component is deployed to an environment, the customer has an option to configure the system to use a self-signed certificate. If the customer does not fully configure the system to leverage the trust database on the clients, it opens up the communication between clients and the server to man-in-the-middle attacks. \n\nIt was discovered that certain parts of the documentation related to the configuration of SSL in Print Deploy were lacking, which could potentially contribute to a misconfiguration of the Print Deploy client installation. PaperCut strongly recommends to use valid certificates to secure installations and to follow the updated documentation to ensure the correct SSL configuration. Those who use private CAs and/or self-signed certificates should make sure to copy their Certification Authority certificate, or their self signed certificate if using only one, to the trust store of their operating system and to the Java key store"},{"lang":"es","value":"PaperCut Print Deploy es un componente opcional que se integra con PaperCut NG/MF, lo que simplifica la implementación y gestión de impresoras. Cuando el componente se implementa en un entorno, el cliente tiene la opción de configurar el sistema para usar un certificado autofirmado. Si el cliente no configura completamente el sistema para aprovechar la base de datos de confianza en los clientes, esto abre la comunicación entre los clientes y el servidor a ataques man-in-the-middle.\n\nSe descubrió que ciertas partes de la documentación relacionada con la configuración de SSL en Print Deploy eran deficientes, lo que podría contribuir a una configuración incorrecta de la instalación del cliente de Print Deploy. PaperCut recomienda encarecidamente usar certificados válidos para proteger las instalaciones y seguir la documentación actualizada para asegurar la configuración SSL correcta. Aquellos que usan CA privadas y/o certificados autofirmados deben asegurarse de copiar su certificado de Autoridad de Certificación, o su certificado autofirmado si usan solo uno, al almacén de confianza de su sistema operativo y al almacén de claves de Java."}],"affected":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","affectedData":[{"vendor":"PaperCut","product":"Print Deploy","defaultStatus":"unaffected","modules":["Print Deploy"],"platforms":["Windows","MacOS"],"versions":[{"version":"0","lessThan":"1.9.2917","versionType":"custom","status":"affected","changes":[{"at":"1.9.2917","status":"unaffected"}]}]}]}],"metrics":{"cvssMetricV40":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-09-04T03:55:27.125442Z","id":"CVE-2025-9785","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","description":[{"lang":"en","value":"CWE-295"}]}],"references":[{"url":"https://www.papercut.com/kb/Main/papercut-ng-mf-security-bulletin-september-2025/","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4"}]}},{"cve":{"id":"CVE-2026-4794","sourceIdentifier":"eb41dac7-0af8-4f84-9f6d-0272772514f4","published":"2026-03-31T01:16:36.743","lastModified":"2026-06-17T10:57:13.600","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in PaperCut NG/MF before 25.0.10 allow authenticated administrator users to inject arbitrary web script or HTML code via different UI fields. This could be used to compromise other admininistrator's sessions or perform unauthorized actions via the administrator's authenticated context (e.g. requires an active login session)."},{"lang":"es","value":"Múltiples vulnerabilidades de cross-site scripting (XSS) en PaperCut NG/MF anteriores a la versión 25.0.10 permiten a usuarios administradores autenticados inyectar scripts web o código HTML arbitrarios a través de diferentes campos de la interfaz de usuario. Esto podría usarse para comprometer las sesiones de otros administradores o realizar acciones no autorizadas a través del contexto autenticado del administrador (por ejemplo, requiere una sesión de inicio de sesión activa)."}],"affected":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","affectedData":[{"vendor":"PaperCut","product":"PaperCut NG/MF","defaultStatus":"unaffected","platforms":["Windows","MacOS","Linux"],"versions":[{"version":"0","lessThan":"25.0.10","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.7,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-31T14:03:53.639112Z","id":"CVE-2026-4794","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionEndExcluding":"25.0.10","matchCriteriaId":"CBDB4B03-5DFF-4983-94F4-27097E8DE93D"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndExcluding":"25.0.10","matchCriteriaId":"C3318324-1141-474E-8AC9-75304DE81432"}]}]}],"references":[{"url":"https://www.papercut.com/kb/Main/papercut-ng-mf-security-bulletin-march-2026/","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-5115","sourceIdentifier":"eb41dac7-0af8-4f84-9f6d-0272772514f4","published":"2026-03-31T01:16:36.900","lastModified":"2026-06-17T10:58:27.573","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"The PaperCut NG/MF (specifically, the embedded application for Konica Minolta devices) is vulnerable to session hijacking. The PaperCut NG/MF Embedded application is a software interface that runs directly on the touch screen of a multi-function device.\n\nIt was internally discovered that the communication channel between the embedded application and the server was insecure, which could leak data including sensitive information that may be used to mount an  attack on the device. Such an attack could potentially be used to steal data or to perform a phishing attack on the end user."},{"lang":"es","value":"El PaperCut NG/MF (específicamente, la aplicación integrada para dispositivos Konica Minolta) es vulnerable al secuestro de sesión. La aplicación integrada de PaperCut NG/MF es una interfaz de software que se ejecuta directamente en la pantalla táctil de un dispositivo multifunción.\n\nSe descubrió internamente que el canal de comunicación entre la aplicación integrada y el servidor era inseguro, lo que podría filtrar datos, incluida información sensible que podría usarse para montar un ataque en el dispositivo. Dicho ataque podría usarse potencialmente para robar datos o para realizar un ataque de phishing en el usuario final."}],"affected":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","affectedData":[{"vendor":"PaperCut","product":"Papercut NG/MF","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"25.0.5","versionType":"semver","status":"affected"},{"version":"0","lessThan":"25.0.9 (KM certified)","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":3.6,"baseSeverity":"LOW","attackVector":"ADJACENT","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"UNREPORTED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-31T13:59:29.117987Z","id":"CVE-2026-5115","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","description":[{"lang":"en","value":"CWE-319"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionEndExcluding":"25.0.5","matchCriteriaId":"52A24870-BFAD-4E33-92AE-1267F5576D5A"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf_konica_minolta:*:*:*:*:*:*:*:*","versionEndExcluding":"25.0.9","matchCriteriaId":"92C27467-EBCE-41E0-BFD3-02D04100EC27"}]}]}],"references":[{"url":"https://www.papercut.com/kb/Main/papercut-ng-mf-security-bulletin-march-2026/","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-6180","sourceIdentifier":"eb41dac7-0af8-4f84-9f6d-0272772514f4","published":"2026-05-05T07:16:00.793","lastModified":"2026-06-17T11:00:26.430","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A race condition exists in PaperCut MF when processing badge-swipe data from certain HP multifunction devices. Under specific network conditions involving dropped packets and out-of-order sequence counters, the server may incorrectly process fragmented data chunks. If a sequence reset notification fails to reach the server, the server may reject the initial data chunk while erroneously accepting subsequent chunks before a connection reset completes.\n\n\n\nThis leads to the registration of a truncated badge ID string. While this typically results in an authentication failure, the vulnerability is compounded in environments utilizing custom badge-ID post-processing scripts. In such configurations, the truncated string may be transformed into a valid ID belonging to a different user, leading to unauthorized session establishment (Incorrect User Login) on the device."}],"affected":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","affectedData":[{"vendor":"PaperCut","product":"PaperCut NG/MF","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"24.1.9","versionType":"semver","status":"affected"},{"version":"0","lessThan":"25.0.10","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":4.1,"baseSeverity":"MEDIUM","attackVector":"PHYSICAL","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-05T13:47:26.998229Z","id":"CVE-2026-6180","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","description":[{"lang":"en","value":"CWE-20"},{"lang":"en","value":"CWE-367"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-367"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionEndExcluding":"24.1.9","matchCriteriaId":"F2AF3AB4-FD10-4DE1-B906-011F45948BD0"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"25.0.2","versionEndExcluding":"25.0.10","matchCriteriaId":"95268D4F-D496-43A9-8926-A4C9611310BA"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndExcluding":"24.1.9","matchCriteriaId":"44FCDCDE-4126-4F4F-89FC-D44924F45C82"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"25.0.2","versionEndExcluding":"25.0.10","matchCriteriaId":"65745C75-AF55-4C86-8D1A-35BB6446F77D"}]}]}],"references":[{"url":"https://www.papercut.com/kb/Main/papercut-ng-mf-and-papercut-hive-security-bulletin-may-2026/","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-6418","sourceIdentifier":"eb41dac7-0af8-4f84-9f6d-0272772514f4","published":"2026-05-05T07:16:00.970","lastModified":"2026-06-17T11:00:48.487","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in the Shared Account Synchronization component of PaperCut MF (version 25.0.4). The application allows administrative users to configure a source path for account data synchronization.\n\n\n\nDue to a lack of proper path validation and sanitization, an authenticated user with administrative privileges can specify arbitrary file paths on the local file system. This allows for the enumeration of directory structures and the unauthorized reading of sensitive text-based configuration or system files.\n\n\n\nWhen the synchronization process is triggered, the application attempts to parse the contents of the specified file, subsequently exposing the data within the application's account management interface. This vulnerability could lead to the disclosure of sensitive system information or configuration details, depending on the permissions of the service account under which the application is running."}],"affected":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","affectedData":[{"vendor":"PaperCut","product":"PaperCut NG/MF","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"25.0.11","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":4.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-05T12:41:28.377029Z","id":"CVE-2026-6418","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","description":[{"lang":"en","value":"CWE-36"},{"lang":"en","value":"CWE-552"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionEndExcluding":"25.0.11","matchCriteriaId":"3A1B8B6C-D36A-42A5-8FC0-57147BF2DD62"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndExcluding":"25.0.11","matchCriteriaId":"2743308B-09C0-47A6-88A6-55B9EC6B777C"}]}]}],"references":[{"url":"https://www.papercut.com/kb/Main/papercut-ng-mf-and-papercut-hive-security-bulletin-may-2026/","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","tags":["Mitigation","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-7824","sourceIdentifier":"eb41dac7-0af8-4f84-9f6d-0272772514f4","published":"2026-05-05T07:16:01.100","lastModified":"2026-06-17T11:03:00.833","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in the PaperCut Hive Ricoh embedded application. When the \"Deep Logging\" (diagnostic) mode is enabled, the application inadvertently records administrative credentials in plain text within the log files.\n\n\n\nAn attacker with administrative access to the PaperCut Hive management portal could remotely enable deep logging and subsequently retrieve sensitive device passwords from the logs after an authorized user authenticates at the device. This exposure allows for the lateral movement or unauthorized configuration of the physical print hardware."}],"affected":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","affectedData":[{"vendor":"PaperCut","product":"PaperCut Hive","defaultStatus":"unaffected","modules":["Ricoh Embedded App"],"versions":[{"version":"0","lessThan":"2.2.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-05T12:40:56.654472Z","id":"CVE-2026-7824","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","description":[{"lang":"en","value":"CWE-532"}]}],"references":[{"url":"https://www.papercut.com/kb/Main/papercut-ng-mf-and-papercut-hive-security-bulletin-may-2026/","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4"}]}},{"cve":{"id":"CVE-2026-6645","sourceIdentifier":"eb41dac7-0af8-4f84-9f6d-0272772514f4","published":"2026-06-22T04:17:13.310","lastModified":"2026-06-23T05:17:05.117","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The application, which typically operates with high-level system privileges, attempts to perform an internal validation check by invoking a secondary system utility using an unqualified file reference.\n\n\n\nBecause the application does not specify an absolute path to this utility, it relies on the operating system's default search order to locate the executable. Under specific conditions, a local attacker with the ability to modify directories within the system's search path could plant a malicious binary that mimics the expected utility. This could result in the malicious code being executed with SYSTEM privileges, leading to a full compromise of the affected host."}],"affected":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","affectedData":[{"vendor":"PaperCut","product":"Print Deploy","defaultStatus":"unaffected","platforms":["Windows"],"versions":[{"version":"0","lessThan":"1.10.4178","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-22T00:00:00+00:00","id":"CVE-2026-6645","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","description":[{"lang":"en","value":"CWE-427"}]}],"references":[{"url":"https://www.papercut.com/kb/Main/papercut-ng-mf-security-bulletin-june-2026/","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4"}]}},{"cve":{"id":"CVE-2026-8793","sourceIdentifier":"eb41dac7-0af8-4f84-9f6d-0272772514f4","published":"2026-08-03T08:17:21.097","lastModified":"2026-09-09T16:03:59.890","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploit this vulnerability to perform unrestricted brute-force or credential-stuffing attacks without triggering account lockout or rate-limiting mechanisms in some configurations."}],"affected":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","affectedData":[{"vendor":"PaperCut","product":"PaperCut NG/MF","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"26.0.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-03T14:32:09.133603Z","id":"CVE-2026-8793","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","description":[{"lang":"en","value":"CWE-307"}]}],"references":[{"url":"https://www.papercut.com/kb/Main/papercut-ng-mf-security-bulletin-3-aug-2026/","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4"}]}},{"cve":{"id":"CVE-2026-8794","sourceIdentifier":"eb41dac7-0af8-4f84-9f6d-0272772514f4","published":"2026-08-03T08:17:21.273","lastModified":"2026-09-09T16:03:59.890","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform username enumeration by measuring response times during login attempts. The system executes a password hash comparison only when a valid account is supplied, creating a measurable timing oracle that reveals account existence."}],"affected":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","affectedData":[{"vendor":"PaperCut","product":"PaperCut NG/MF","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"26.0.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-03T14:29:59.343562Z","id":"CVE-2026-8794","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","description":[{"lang":"en","value":"CWE-208"}]}],"references":[{"url":"https://www.papercut.com/kb/Main/papercut-ng-mf-security-bulletin-3-aug-2026/","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4"}]}},{"cve":{"id":"CVE-2026-81578","sourceIdentifier":"eb41dac7-0af8-4f84-9f6d-0272772514f4","published":"2026-08-28T16:18:29.600","lastModified":"2026-09-14T00:16:56.207","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the  completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations."}],"affected":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","affectedData":[{"vendor":"PaperCut","product":"PaperCut MF/NG","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"24.1.10","versionType":"semver","status":"affected"},{"version":"25.0.0","lessThan":"25.0.13","versionType":"semver","status":"affected"},{"version":"26.0.0","lessThan":"26.0.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-28T00:00:00+00:00","id":"CVE-2026-81578","options":[{"exploitation":"active"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2026-08-31","cisaActionDue":"2026-09-14","cisaRequiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","cisaVulnerabilityName":"PaperCut NG/MF Missing Authentication for Critical Function Vulnerability","weaknesses":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","description":[{"lang":"en","value":"CWE-305"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionEndExcluding":"24.1.9","matchCriteriaId":"F2AF3AB4-FD10-4DE1-B906-011F45948BD0"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"25.0.2","versionEndExcluding":"25.0.12","matchCriteriaId":"8F6ED0B8-62DC-4CF9-9810-2CCB824FBCA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"26.0.2","versionEndExcluding":"26.0.4","matchCriteriaId":"51E91B81-E311-4BB9-A753-671F0C59E7F7"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndExcluding":"24.1.9","matchCriteriaId":"44FCDCDE-4126-4F4F-89FC-D44924F45C82"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"25.0.2","versionEndExcluding":"25.0.12","matchCriteriaId":"9E727ABD-0007-424D-AB07-FB7816E43792"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"26.0.2","versionEndExcluding":"26.0.4","matchCriteriaId":"3938B71A-CB14-4017-A037-7D5F08DAFB13"}]}]}],"references":[{"url":"https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","tags":["Patch","Vendor Advisory"]},{"url":"https://github.com/rapid7/metasploit-framework/pull/21842","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Issue Tracking","Patch"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-81578","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Patch","Third Party Advisory","US Government Resource"]}]}},{"cve":{"id":"CVE-2026-82078","sourceIdentifier":"eb41dac7-0af8-4f84-9f6d-0272772514f4","published":"2026-08-28T16:18:31.240","lastModified":"2026-09-14T00:16:56.777","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process."}],"affected":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","affectedData":[{"vendor":"PaperCut","product":"PaperCut MF/NG","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"24.1.10","versionType":"semver","status":"affected"},{"version":"25.0.0","lessThan":"25.0.13","versionType":"semver","status":"affected"},{"version":"26.0.0","lessThan":"26.0.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.4,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.3,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-28T00:00:00+00:00","id":"CVE-2026-82078","options":[{"exploitation":"active"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2026-08-31","cisaActionDue":"2026-09-14","cisaRequiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","cisaVulnerabilityName":"PaperCut NG/MF Unsafe Reflection Vulnerability","weaknesses":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","description":[{"lang":"en","value":"CWE-470"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionEndExcluding":"24.1.9","matchCriteriaId":"F2AF3AB4-FD10-4DE1-B906-011F45948BD0"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"25.0.2","versionEndExcluding":"25.0.12","matchCriteriaId":"8F6ED0B8-62DC-4CF9-9810-2CCB824FBCA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*","versionStartIncluding":"26.0.2","versionEndExcluding":"26.0.4","matchCriteriaId":"51E91B81-E311-4BB9-A753-671F0C59E7F7"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionEndExcluding":"24.1.9","matchCriteriaId":"44FCDCDE-4126-4F4F-89FC-D44924F45C82"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"25.0.2","versionEndExcluding":"25.0.12","matchCriteriaId":"9E727ABD-0007-424D-AB07-FB7816E43792"},{"vulnerable":true,"criteria":"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*","versionStartIncluding":"26.0.2","versionEndExcluding":"26.0.4","matchCriteriaId":"3938B71A-CB14-4017-A037-7D5F08DAFB13"}]}]}],"references":[{"url":"https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","tags":["Patch","Vendor Advisory"]},{"url":"https://github.com/rapid7/metasploit-framework/pull/21842","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Issue Tracking","Patch"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-82078","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Patch","Third Party Advisory","US Government Resource"]}]}},{"cve":{"id":"CVE-2026-14780","sourceIdentifier":"eb41dac7-0af8-4f84-9f6d-0272772514f4","published":"2026-09-24T06:17:00.567","lastModified":"2026-09-25T04:17:34.103","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization and access restrictions within the embedded execution engine. An authenticated user with administrative access to the management interface can supply a malicious script that escapes the runtime sandbox.  \n\nA successful execution enables an attacker to run unauthorized operating system commands with administrative privileges on the host operating system."}],"affected":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","affectedData":[{"vendor":"PaperCut","product":"PaperCut NG/MF","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"25.0.12","versionType":"semver","status":"affected"},{"version":"26.0.0","lessThan":"26.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-24T00:00:00+00:00","id":"CVE-2026-14780","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"references":[{"url":"https://www.papercut.com/kb/Main/security-bulletin-sep-2026/","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4"}]}},{"cve":{"id":"CVE-2026-11744","sourceIdentifier":"eb41dac7-0af8-4f84-9f6d-0272772514f4","published":"2026-09-24T07:16:32.100","lastModified":"2026-09-24T21:08:22.573","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"An input validation vulnerability exists in the PaperCut Hive embedded application for Ricoh devices. The application fails to properly sanitize input received during the NFC card reading process before passing it to the application's web view interface. A local attacker with physical access to the device and a specially crafted NFC card or emulator could exploit this flaw to execute arbitrary code within the context of the application's user interface. This could result in unauthorized actions or information disclosure."}],"affected":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","affectedData":[{"vendor":"PaperCut","product":"PaperCut Hive","defaultStatus":"unaffected","modules":["Embedded App for Ricoh"],"versions":[{"version":"2.0.0","lessThan":"2.3.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":3.8,"baseSeverity":"LOW","attackVector":"PHYSICAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"UNREPORTED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-24T12:40:59.451126Z","id":"CVE-2026-11744","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://www.papercut.com/kb/Main/security-bulletin-sep-2026/","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4"}]}},{"cve":{"id":"CVE-2026-82077","sourceIdentifier":"eb41dac7-0af8-4f84-9f6d-0272772514f4","published":"2026-09-24T07:16:33.457","lastModified":"2026-09-25T04:17:47.677","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an authenticated administrator to execute arbitrary commands on the underlying host via crafted fax provider settings."}],"affected":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","affectedData":[{"vendor":"PaperCut","product":"PaperCut NG/MF","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"25.0.13","versionType":"semver","status":"affected"},{"version":"26.0.0","lessThan":"26.0.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-24T00:00:00+00:00","id":"CVE-2026-82077","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","description":[{"lang":"en","value":"CWE-22"},{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://www.papercut.com/kb/Main/security-bulletin-sep-2026/","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4"}]}},{"cve":{"id":"CVE-2026-87739","sourceIdentifier":"eb41dac7-0af8-4f84-9f6d-0272772514f4","published":"2026-09-24T07:16:34.780","lastModified":"2026-09-24T21:08:22.573","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report generation. By submitting report generation requests without valid credentials, an attacker can generate reports and gain unauthorized access to sensitive information."}],"affected":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","affectedData":[{"vendor":"PaperCut","product":"PaperCut NG/MF","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"25.0.13","versionType":"semver","status":"affected"},{"version":"26.0.0","lessThan":"26.0.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"YES","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-24T12:42:13.527939Z","id":"CVE-2026-87739","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"eb41dac7-0af8-4f84-9f6d-0272772514f4","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"references":[{"url":"https://www.papercut.com/kb/Main/security-bulletin-sep-2026/","source":"eb41dac7-0af8-4f84-9f6d-0272772514f4"}]}}]}