CVE-2023-27351

9.5 CISA KEV

PaperCut · NG/MF

An improper authentication vulnerability in the PaperCut NG/MF SecurityRequestFilter class allows unauthenticated attackers to bypass authentication and access sensitive user information.

Executive summary

This critical authentication bypass vulnerability in PaperCut NG/MF is currently being actively exploited in the wild to facilitate ransomware attacks.

Vulnerability

The flaw resides in the SecurityRequestFilter class, resulting from an improper implementation of the authentication algorithm. This allows unauthenticated, network-reachable attackers to bypass system authentication entirely.

Business impact

The exploitation of this vulnerability poses a severe risk, as it allows unauthorized actors to extract sensitive user account information, including hashed passwords, from print management servers. Given the CVSS score of 9.5, the potential for total system compromise is high. This flaw has been directly linked to the deployment of Cl0p and LockBit ransomware families, leading to significant potential for data exfiltration and operational disruption.

Remediation

Immediate Action: Upgrade all instances of PaperCut NG and MF to version 20.1.7, 21.2.11, 22.0.9, or later immediately.

Proactive Monitoring: Monitor server logs for unauthorized access attempts or unusual patterns originating from the print management interface.

Compensating Controls: If patching is delayed, restrict network access to the PaperCut management port to trusted internal IP addresses only.

Exploitation status

Public Exploit Available: Yes (Nuclei detection templates exist).

Analyst recommendation

Due to the confirmed active exploitation by ransomware groups, this vulnerability represents an immediate and critical threat to organizational integrity. Administrators must prioritize the application of the vendor-provided patches listed above to prevent unauthorized access and potential ransomware deployment.

More PaperCut CVEs

Sources

Originally found and disclosed by Piotr Bazydlo (@chudypb) of Trend Micro Zero Day Initiative, per the CVE Program record.