CVE-2024-1882
Estado: AnalizadaAlta (7.2)—
This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for remote code execution on the server hosting the PaperCut NG/MF application server.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.41%
- Percentil entre todas las CVEs puntuadas: 72
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-76
- NVD-CWE-Other
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-1882",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-1882",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-03-16T04:00:55.398174Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "eb41dac7-0af8-4f84-9f6d-0272772514f4",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.2,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.2
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.2,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.2
}
]
},
"affected": [
{
"source": "eb41dac7-0af8-4f84-9f6d-0272772514f4",
"affectedData": [
{
"vendor": "PaperCut",
"product": "PaperCut NG, PaperCut MF",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "23.0.7",
"status": "unaffected"
}
],
"version": "0",
"lessThan": "23.0.7",
"versionType": "custom"
},
{
"status": "affected",
"changes": [
{
"at": "22.1.5",
"status": "unaffected"
}
],
"version": "0",
"lessThan": "22.1.5",
"versionType": "custom"
},
{
"status": "affected",
"changes": [
{
"at": "21.2.14",
"status": "unaffected"
}
],
"version": "0",
"lessThan": "21.2.14",
"versionType": "custom"
},
{
"status": "affected",
"changes": [
{
"at": "20.1.10",
"status": "unaffected"
}
],
"version": "0",
"lessThan": "20.1.10",
"versionType": "custom"
}
],
"platforms": [
"MacOS",
"Linux",
"Windows"
],
"defaultStatus": "affected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*"
],
"vendor": "papercut",
"product": "papercut_ng",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "23.0.7",
"versionType": "custom"
},
{
"status": "affected",
"version": "0",
"lessThan": "22.1.5",
"versionType": "custom"
},
{
"status": "affected",
"version": "0",
"lessThan": "21.2.14",
"versionType": "custom"
},
{
"status": "affected",
"version": "0",
"lessThan": "20.1.10",
"versionType": "custom"
}
],
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*"
],
"vendor": "papercut",
"product": "papercut_mf",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "23.0.7",
"versionType": "custom"
},
{
"status": "affected",
"version": "0",
"lessThan": "22.1.5",
"versionType": "custom"
},
{
"status": "affected",
"version": "0",
"lessThan": "21.2.14",
"versionType": "custom"
},
{
"status": "affected",
"version": "0",
"lessThan": "20.1.10",
"versionType": "custom"
}
],
"defaultStatus": "affected"
}
]
}
],
"published": "2024-03-14T04:15:08.003",
"references": [
{
"url": "https://www.papercut.com/kb/Main/Security-Bulletin-March-2024",
"tags": [
"Vendor Advisory"
],
"source": "eb41dac7-0af8-4f84-9f6d-0272772514f4"
},
{
"url": "https://www.papercut.com/kb/Main/Security-Bulletin-March-2024",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "eb41dac7-0af8-4f84-9f6d-0272772514f4",
"description": [
{
"lang": "en",
"value": "CWE-76"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for remote code execution on the server hosting the PaperCut NG/MF application server."
},
{
"lang": "es",
"value": "Esta vulnerabilidad permite que un usuario administrador ya autenticado cree un payload malicioso que podría aprovecharse para la ejecución remota de código en el servidor que aloja el servidor de aplicaciones PaperCut NG/MF."
}
],
"lastModified": "2026-06-17T07:05:12.720",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "87E57A99-6580-4C5D-AD49-2C77153698B5",
"versionEndExcluding": "20.1.10"
},
{
"criteria": "cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AC862C5A-C51D-455A-BA4C-62AF4B5593D6",
"versionEndExcluding": "21.2.14",
"versionStartIncluding": "21.0.0"
},
{
"criteria": "cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3B444455-3DE9-4268-AED3-9457016B833F",
"versionEndExcluding": "22.1.5",
"versionStartIncluding": "22.0.0"
},
{
"criteria": "cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "06311316-1937-41A4-BEE2-57F7C4F6B6BC",
"versionEndExcluding": "23.0.7",
"versionStartIncluding": "23.0.1"
},
{
"criteria": "cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F7A1BAB4-D3AC-4A06-B2AB-E46DED8CB19D",
"versionEndExcluding": "20.1.10"
},
{
"criteria": "cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "570DCFBC-7689-4E77-A8BF-8F310545EDE3",
"versionEndExcluding": "21.2.14",
"versionStartIncluding": "21.0.0"
},
{
"criteria": "cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "728ECAA8-FE3E-4F6D-8862-AF0C100C6699",
"versionEndExcluding": "22.1.5",
"versionStartIncluding": "22.0.0"
},
{
"criteria": "cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7155AC1E-E4C8-4EF5-B593-7C924AF0C625",
"versionEndExcluding": "23.0.7",
"versionStartIncluding": "23.0.1"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "387021A0-AF36-463C-A605-32EA7DAC172E"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"
},
{
"criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "eb41dac7-0af8-4f84-9f6d-0272772514f4"
}