Impact
The vulnerability allows an unauthenticated remote attacker to perform unrestricted brute‑force or credential‑stuffing attacks against the login component because account lockout or rate‑limiting mechanisms are not properly enforced. This enables the attacker to obtain valid credentials for any user account, leading to unauthorized access, data breaches or privileged escalation. The weakness is identified as CWE‑307: Account Lockout Policy Does Not Prevent Brute Force Attack.
Affected Systems
PaperCut NG and PaperCut MF are affected. No specific version information is listed; the issue applies to all releases that lack proper brute‑force protection in their login component.
Risk and Exploitability
The CVSS base score of 6.9 indicates moderate‑to‑high severity. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known active exploitation at this time. The likely attack vector is remote, unauthenticated, through the application’s authentication interface. An attacker with network access to the PaperCut instance can launch automated login attempts without triggering lockout or throttling, potentially gaining access to user accounts and sensitive printing data.
OpenCVE Enrichment