Impact
An improper access control flaw in the web management interface of PaperCut MF and PaperCut NG permits an unauthenticated attacker to invoke certain administrative operations before the system completes its access validation. The flaw allows the attacker to alter system configuration settings without authentication, effectively bypassing the intended authorization controls.
Affected Systems
PaperCut’s PaperCut MF and PaperCut NG products are affected. No specific version range is listed in the vendor advisories, so all deployed installations are potentially vulnerable until a patch is applied.
Risk and Exploitability
The vulnerability scores a high CVSS of 8.8, indicating substantial impact if exploited. The EPSS score is 85%, indicating a high probability of exploitation. It is now listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector likely requires the ability to send HTTP requests to the web management interface, which can be reachable from external networks unless protected by network-segmentation. Given the high EPSS, the likelihood of exploitation is markedly higher, and the high severity and KEV status warrant prompt action.
OpenCVE Enrichment