ZDI-CAN-22165: ZDI-24-779: PaperCut NG VendorKeys Hardcoded Credentials Authentication Bypass Vulnerability
Published Jun 18, 2024
·Updated
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2024-1223.
Affected Software
1 affected component
PaperCut NG
Event History
Jun 18, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-22165?
The vulnerability ZDI-CAN-22165 has a CVSS rating of 8.2, indicating high severity.
2
How do I fix ZDI-CAN-22165?
To fix vulnerability ZDI-CAN-22165, apply the latest security patches provided by PaperCut NG.
3
Who is affected by ZDI-CAN-22165?
All installations of PaperCut NG are affected by vulnerability ZDI-CAN-22165.
4
What type of attack can exploit ZDI-CAN-22165?
ZDI-CAN-22165 allows remote attackers to bypass authentication without needing to authenticate.
5
What is the impact of exploiting ZDI-CAN-22165?
Exploiting ZDI-CAN-22165 could allow unauthorized access to sensitive functions of affected PaperCut NG installations.