This vulnerability potentially allows unauthorized enumeration of information from the embedded device APIs. An attacker must already have existing knowledge of some combination of valid usernames, device names and an internal system key. For such an attack to be successful the system must be in a specific runtime state.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Sep 2024 04:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-200 | |
Metrics |
ssvc
|
Thu, 26 Sep 2024 04:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | Improper authorization controls in PaperCut NG/MF | Improper authorization controls in PaperCut NG/MF |
Weaknesses | CWE-488 |
MITRE
Status: PUBLISHED
Assigner: PaperCut
Published: 2024-03-14T03:04:43.588Z
Updated: 2024-09-26T03:50:15.610Z
Reserved: 2024-02-05T04:34:01.599Z
Link: CVE-2024-1223
Vulnrichment
Updated: 2024-08-01T18:33:25.230Z
NVD
Status : Awaiting Analysis
Published: 2024-03-14T03:15:07.580
Modified: 2024-09-26T04:15:07.270
Link: CVE-2024-1223
Redhat
No data.