bk99.de entertain the web since 1997

Print management solution: security holes endanger PaperCut servers

Summary

In August 2023 PaperCut closed two high-rated holes in its print management software. Via CVE-2023-3486, attackers could upload files without logging in and fill up the hard disk; via CVE-2023-39143 they could view and modify files, and according to Horizon3 even execute code. The Windows hole required the External Device Integration function, which was active by default in PaperCut NG Commercial and MF.

Ideas

  • Print servers are full servers with their own attack surface.
  • Uncontrolled uploads can bring systems down simply by filling up storage.
  • A simple curl call with path traversal shows whether a system is vulnerable.
  • Without a patch, restricting access to known IP addresses helps.

Insights

  • Infrastructure services such as print management are often overlooked when patching.
  • Integration functions enabled by default enlarge the attack surface unnoticed.

Facts

  • The secured version was PaperCut NG/MF 22.1.3.
  • PaperCut had already had to close a critical hole in April 2023.

References

Critique

  • The report gives the test command but does not explain how to interpret a positive result.

Recommendations

  • Include print and scan servers in regular patch management.
  • Only allow access to management servers from defined networks.

Read the original article

Search the Web Archive