Search/papercut
Vendor

papercut

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
mobility print server
Connections
10 relationships
CISA Warns of Exploited Critical Vulnerabilities in Cisco Identity Services Engine
The US Cybersecurity and Infrastructure Security Agency (CISA) added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on July 28. These include two highly critical vulnerabilities in Cisco Identity Services Engine (ISE) Software, a network security policy management platform that provides secure access control, authentication, authorization and accounting (AAA) services for users and devices connecting to enterprise networks. Both vulnerabilities, tracked as CVE-2025-20281 and CVE-2025-20337, were discovered by security researchers working with the Trend Micro Zero Day Initiative and disclosed by Cisco on June 25. They have been identified due to insufficient validation of a user-supplied input in a specific API of Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC). Attackers can exploit each by submitting a crafted API request. When exploited, it allows an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. It can lead the attacker to obtain root privileges on an affected device. Both vulnerabilities affect the following versions of Cisco ISE: 3.3.0 3.3 Patch 2 3.3 Patch 1 3.3 Patch 3 3.4.0 3.3 Patch 4 3.4 Patch 1 3.3 Patch 5 3.3 Patch 6 Additionally, CVE-2025-20337 also affects Cisco ISE-PIC’s versions 3.1.0, 3.2.0, 3.3.0 and 3.4.0. They are both rated with the highest severity level, with a CVSS3.1 score of 10. Cisco has released patches for each affected version of Cisco ISE and Cisco ISE-PIC. Cisco Product Security Incident Response Team (PSIRT) has become aware of attempted exploitation of both vulnerabilities in the wild. CISA has set August 18 as the deadline for remediation, requiring organizations to address these critical security vulnerabilities within the next three weeks. No workaround is available besides applying the patches. The third vulnerability added to CISA’s KEV list on July 28, CVE-2023-2533, is a high-severity cross-site request forgery (CSRF) vulnerability affecting PaperCut Next Generation (NG) and Multi-Function (MF), print management software solutions designed to help organizations control, monitor and optimize printing, copying, scanning and faxing across their networks.
infosecurity-magazine.comJul 29, 2025extracted
PaperCut: rilevato sfruttamento in rete della CVE-2023-2533
PaperCut: rilevato sfruttamento in rete della CVE-2023-2533 Alert AL03/250729/CSIRT-ITA Sintesi Rilevato lo sfruttamento attivo in rete della vulnerabilità CVE-2023–2533 – già sanata dal vendor a giugno 2023 – presente in PaperCut NG/MF, soluzione software per la gestione e il controllo delle stampe. Tipologia Remote Code Execution Tampering Descrizione Rilevato lo sfruttamento attivo in rete della vulnerabilità CVE-2023–2533 – già sanata dal vendor a giugno 2023 – presente in PaperCut NG/MF, soluzione software per la gestione e il controllo delle stampe. Tale vulnerabilità, di tipo “Cross-Site Request Forgery” e con score CVSS v3.1 pari a 8.8, potrebbe essere sfruttata da un utente malintenzionato remoto inducendo un amministratore, con sessione attiva sull’interfaccia di amministrazione di PaperCut, a cliccare su un link malevolo opportunamente predisposto. In caso di sfruttamento andato a buon fine, l’utente malintenzionato riuscirebbe ad alterare le configurazioni di sicurezza ed eseguire codice arbitrario sui sistemi interessati. Per eventuali ulteriori approfondimenti si consiglia di consultare il bollettino di sicurezza, disponibile nella sezione Riferimenti. Prodotti e versioni affette PaperCut MF e PaperCut NG versioni precedenti alla 20.1.8 21.x, versioni precedenti alla 21.2.12 22.x, versioni precedenti alla 22.1.1 Azioni di mitigazione Ove non già provveduto, si raccomanda di aggiornare i prodotti vulnerabili seguendo le indicazioni del bollettino di sicurezza riportato nella sezione Riferimenti.
acn.gov.itJul 29, 2025extracted
CISA Adds PaperCut NG/MF CSRF Vulnerability to KEV Catalog Amid Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security vulnerability impacting PaperCutNG/MF print management software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The vulnerability, tracked as CVE-2023-2533 (CVSS score: 8.4), is a cross-site request forgery (CSRF) bug that could result in remote code execution. "PaperCut NG/MF contains a cross-site request forgery (CSRF) vulnerability, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code," CISA said in an alert. PaperCut NG/MF is commonly used by schools, businesses, and government offices to manage print jobs and control network printers. Because the admin console typically runs on internal web servers, an exploited vulnerability here could give attackers an easy foothold into broader systems if overlooked. In a potential attack scenario, a threat actor could leverage the flaw to target an admin user with a current login session, and deceive them into clicking on a specially crafted link that leads to unauthorized changes. It's currently not known how the vulnerability is being exploited in real-world attacks. But given that shortcomings in the software solution have been abused by Iranian nation-state actors as well as e-crime groups like Bl00dy, Cl0p, and LockBit ransomware for initial access, it's essential that users apply necessary updates, if not already. At the time of writing, no public proof-of-concept is available, but attackers could exploit the bug through a phishing email or a malicious site that tricks a logged-in admin into triggering the request. Mitigation requires more than patching—organizations should also review session timeouts, restrict admin access to known IPs, and enforce strong CSRF token validation. Pursuant to Binding Operational Directive (BOD) 22-01, Federal Civilian Executive Branch (FCEB) agencies are required to update their instances to a patched version by August 18, 2025. Admins should cross-check with MITRE ATT&CK techniques like T1190 (Exploit Public-Facing Application) and T1071 (Application Layer Protocol) to align detection rules. For broader context, tracking PaperCut incidents in relation to ransomware entry points or initial access vectors can help shape long-term hardening strategies.
thehackernews.comJul 29, 2025extracted
CISA flags PaperCut RCE bug as exploited in attacks, patch now
CISA warns that threat actors are exploiting a high-severity vulnerability in PaperCut NG/MF print management software, which can allow them to gain remote code execution in cross-site request forgery (CSRF) attacks. The software developer says that more than 100 million users use its products across over 70,000 organizations worldwide. The security flaw (tracked as CVE-2023-2533 and patched in June 2023) can allow an attacker to alter security settings or execute arbitrary code if the target is an admin with a current login session, and successful exploitation typically requires tricking an admin into clicking a maliciously crafted link. CISA has yet to share details regarding these ongoing attacks, but it has added the vulnerability to its Known Exploited Vulnerabilities Catalog, giving Federal Civilian Executive Branch (FCEB) agencies three weeks to patch their systems by August 18, as mandated by the November 2021 Binding Operational Directive (BOD) 22-01. While BOD 22-01 targets U.S. federal agencies, the cybersecurity agency encourages all organizations, including those in the private sector, to prioritize patching this actively exploited security bug as soon as possible. "These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise," CISA cautioned on Monday. Non-profit security organization Shadowserver currently tracks over 1,100 PaperCut MF and NG servers that are exposed online, although not all are vulnerable to CVE-2023-2533 attacks. PaperCut flaws exploited by ransomware gangs Although CISA has no evidence that CVE-2023-2533 is being targeted in ransomware attacks, PaperCut servers have been previously breached by ransomware gangs in 2023 by exploiting a critical, unauthenticated remote code execution (RCE) vulnerability (CVE–2023–27350) and a high-severity information disclosure flaw (CVE–2023–27351). In April 2023, Microsoft linked the attacks targeting PaperCut servers to the LockBit and Clop ransomware gangs, who used their access to compromised systems to steal corporate data. Almost two weeks later, Microsoft also revealed that Iranian state-backed hacking groups (tracked as Muddywater and APT35) also joined the attacks. As the company explained at the time, the threat actors exploited the 'Print Archiving' feature, which is designed to save all documents sent through PaperCut printing servers. CISA added CVE-2023–27350 to its catalog of actively exploited vulnerabilities on April 21, 2023, ordering U.S. federal agencies to secure their servers by May 12, 2023. One month later, CISA and the FBI issued a joint advisory warning that the Bl00dy Ransomware gang had also begun exploiting the CVE-2023–27350 RCE vulnerability to gain initial access to the networks of educational organizations. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJul 28, 2025extracted