19/04/2023

Critical and High Vulnerabilities in PaperCut – Actively Exploited

Summary:

As identified by Jisc, one of our trusted support partners a pair of vulnerabilities have been identified in PaperCut MF/NG print solutions. ZDI-CAN-18987 allows an attacker to bypass authentication on a vulnerable PaperCut Application Server. This may be exploited remotely.

ZDI-CAN-19226 may allow an unauthenticated attacker, under certain circumstances, to pull information about a user stored within PaperCut MF or NG. This information includes usernames, full names, email addresses, office/department information and any card numbers associated with a user. The attacker can also retrieve the hashed passwords for internal PaperCut created users only. Note: This does not include password hashes for users sync’d from directory sources such as M365, Google Workspace, Active Directory etc. This vulnerability can be exploited remotely and without the need to log in. 

Vulnerable Versions:

ZDI-CAN-18987 / PO-1216 (CVSS 9.8):
PaperCut MF or NG version 8.0 or later, on all OS platforms

Application Servers are impacted.

Site Servers are impacted.

ZDI-CAN-19226 / PO-1219 (CVSS 8.2):
PaperCut MF or NG version 15.0 or later, on all OS platforms

Application Servers are impacted.

Recommendation(s):

Upgrade Papercut Application Servers to the latest fixed versions.
Both of these vulnerabilities have been fixed in PaperCut MF and PaperCut NG versions 20.1.7, 21.2.11 and 22.0.9 and later

If you believe your server has been compromised, it is recommended to isolate and wipe the application server and rebuild from a backup point prior to the identified compromise behaviour.

Jisc CSIRT is now aware of multiple attempts to exploit these vulnerabilities with one being a successful exploitation leading to compromise. Do not hesitate to contact Jisc CSIRT if your environment is at risk and you would benefit from incident response support.

References:

Questions:

If you have any questions or concerns about this advisory, please contact us via our support desk – support@empsn.org.uk

Keeping Up To Date With Us Is Easy, Sign Up To Our Newsletter Today!

Stay in touch with emPSN, so that you get the latest e-safety advice and invites to our community events.

Our partners