Back

MEDIUM

Improper authorization controls in PaperCut NG/MF

Published Mar 14, 2024

Description

This vulnerability potentially allows unauthorized enumeration of information from the embedded device APIs. An attacker must already have existing knowledge of some combination of valid usernames, device names and an internal system key. For such an attack to be successful the system must be in a specific runtime state.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner PaperCut
Published Mar 14, 2024
Updated Sep 26, 2024
Reserved Feb 5, 2024
CISA Vulnrichment
Updated Mar 14, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a