{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2023-27350",
  "revision": 1,
  "title": "PaperCut MF/NG — Authentication Bypass to System-Level RCE",
  "summary": "PaperCut print servers expose a setup class that never checks who is calling it, so an unauthenticated attacker on the network walks past the login screen and runs code with the highest privileges on the print server.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 9.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.99999,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": true,
    "attack_complexity": "low",
    "kev_added": "2023-04-21",
    "prerequisites": "Network access to an affected PaperCut MF or NG installation. No credentials needed."
  },
  "remediation": {
    "patch_available": true
  },
  "mitre_attack": [
    "T1190"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Update PaperCut MF and NG per the vendor bulletin, keep the admin interface off the public internet, and check print servers for scripts and accounts you did not create.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "title",
        "summary",
        "cvss",
        "severity",
        "exploitation.attack_complexity",
        "exploitation.prerequisites",
        "exploitation.exploit_available",
        "references"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-27350",
      "retrieved_at": "2026-08-07T07:53:55.549Z",
      "confidence": "high",
      "extractor": "claude-code"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "remediation.patch_available",
        "recommended_action"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-08-07T07:53:55.549Z",
      "confidence": "high",
      "extractor": "claude-code"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2023-27350",
      "retrieved_at": "2026-08-07T07:53:55.549Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27350",
      "label": "NVD record"
    },
    {
      "type": "vendor_advisory",
      "url": "https://www.papercut.com/kb/Main/PO-1216-and-PO-1219",
      "label": "PaperCut security bulletin"
    },
    {
      "type": "writeup",
      "url": "https://news.sophos.com/en-us/2023/04/27/increased-exploitation-of-papercut-drawing-blood-around-the-internet/",
      "label": "Sophos: exploitation in the wild"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-27350",
      "label": "CISA Known Exploited Vulnerabilities entry"
    }
  ],
  "published_at": "2023-04-20T16:15:07.653Z",
  "issued_at": "2026-08-07T07:53:55.549Z",
  "tags": [
    "papercut",
    "print-management",
    "access-control",
    "authentication-bypass",
    "kev",
    "ransomware"
  ]
}
