Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-3486

Опубликовано: 25 июл. 2023
Источник: nvd
CVSS3: 8.2
CVSS3: 7.5
EPSS Низкий

Описание

An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated attacker to upload arbitrary files to the PaperCut NG host’s file storage. This could exhaust system resources and prevent the service from operating as expected.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*
Версия до 22.1.3 (исключая)
cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*
Версия до 22.1.3 (исключая)

EPSS

Процентиль: 85%
0.02434
Низкий

8.2 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-434
CWE-434

Связанные уязвимости

CVSS3: 8.2
github
больше 2 лет назад

An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated attacker to upload arbitrary files to the PaperCut NG host’s file storage. This could exhaust system resources and prevent the service from operating as expected.

EPSS

Процентиль: 85%
0.02434
Низкий

8.2 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-434
CWE-434