CVE-2023-27351
9.5 CISA KEVPaperCut · NG/MF
An improper authentication vulnerability in the PaperCut NG/MF SecurityRequestFilter class allows unauthenticated attackers to bypass authentication and access sensitive user information.
Executive summary
This critical authentication bypass vulnerability in PaperCut NG/MF is currently being actively exploited in the wild to facilitate ransomware attacks.
Vulnerability
The flaw resides in the SecurityRequestFilter class, resulting from an improper implementation of the authentication algorithm. This allows unauthenticated, network-reachable attackers to bypass system authentication entirely.
Business impact
The exploitation of this vulnerability poses a severe risk, as it allows unauthorized actors to extract sensitive user account information, including hashed passwords, from print management servers. Given the CVSS score of 9.5, the potential for total system compromise is high. This flaw has been directly linked to the deployment of Cl0p and LockBit ransomware families, leading to significant potential for data exfiltration and operational disruption.
Remediation
Immediate Action: Upgrade all instances of PaperCut NG and MF to version 20.1.7, 21.2.11, 22.0.9, or later immediately.
Proactive Monitoring: Monitor server logs for unauthorized access attempts or unusual patterns originating from the print management interface.
Compensating Controls: If patching is delayed, restrict network access to the PaperCut management port to trusted internal IP addresses only.
Exploitation status
Public Exploit Available: Yes (Nuclei detection templates exist).
Analyst recommendation
Due to the confirmed active exploitation by ransomware groups, this vulnerability represents an immediate and critical threat to organizational integrity. Administrators must prioritize the application of the vendor-provided patches listed above to prevent unauthorized access and potential ransomware deployment.
More PaperCut CVEs
Sources
Originally found and disclosed by Piotr Bazydlo (@chudypb) of Trend Micro Zero Day Initiative, per the CVE Program record.