DFIELDSOLUTIONS

Fallstudie · 2025 · Sicherheit

Ein alter Druckserver, vergessen irgendwo im Netzwerk.Ein funktionierender Exploit in vier Sekunden vorgeführt. Das Team hat gesehen, dass jeder von außen den Druckserver vollständig hätte übernehmen können.

CVE-2023-27350 is a PaperCut MF/NG authentication-bypass flaw (CVSS 9.8). The studio's PoC chains the SetupCompleted bypass with the Print Scripting console, then drops a Windows SYSTEM-level reverse shell · end-to-end recon → exploit → shell, in 4 seconds, scripted in Python.

  • Python
  • requests
  • PaperCut MF/NG
  • Netcat
Interner Build, keine öffentliche URL
CVE-2023-27350 · PaperCut RCE PoC

Im Einsatz

CVE-2023-27350 · PaperCut RCE PoC — Startzustand
Startzustand
CVE-2023-27350 · PaperCut RCE PoC — In Benutzung
In Benutzung
CVE-2023-27350 · PaperCut RCE PoC — Ergebnis
Ergebnis

Überblick

9.8
CVSS-Wert
1
HTTP POST zum Umgehen
4 sec
Aufklärung → SYSTEM-Shell
SYSTEM
Rechteebene der Reverse Shell

PoC exploiting the PaperCut MF/NG authentication-bypass flaw (CVSS 9.8). The SetupCompleted page skips auth, and the Print Scripting console runs arbitrary code from there · our script chains both and drops a Windows SYSTEM-level reverse shell on the attacker machine. Full end-to-end demo: recon, payload, shell.

Was ausgeliefert wurde

Was es tut

  • Exploits PaperCut MF/NG below 20.1.7 / 21.2.11 / 22.0.9
  • Python PoC · 1 HTTP POST to bypass, 1 to run code
  • SYSTEM / root reverse shell back to the attacker box
  • Clean recon → exploit → shell demo in 4 seconds

Das Problem

  • Print servers rarely get security audits yet sit in the middle of the network
  • 'Hidden' admin pages are often reachable without auth, SetupCompleted is the textbook case
  • Print Scripting runs JS-spawned processes with no sandbox · that becomes SYSTEM

Warum es zählt

  • Concrete proof that a forgotten PaperCut box gets owned in minutes
  • Shows why closing ports isn't the fix · logic flaws are the real attack surface
  • Exact remediation path: upgrade to 20.1.7 / 21.2.11 / 22.0.9+ and segment the print LAN

Wie es entstand

  1. 01 · RECON

    Identify the vulnerable PaperCut server.

    Banner-grab the build version via the management UI · everything below 20.1.7 / 21.2.11 / 22.0.9 is in scope. Print servers usually sit unsegmented in the middle of internal LANs.

  2. 02 · BYPASS

    SetupCompleted skips auth.

    A single POST to the SetupCompleted handler walks the server past authentication into an admin-equivalent state. The PoC sends one request and is in.

  3. 03 · SHELL

    Print Scripting → SYSTEM reverse shell.

    Print Scripting console runs JS-spawned processes with no sandbox · cmd.exe under SYSTEM privilege. Netcat catches the reverse shell on the attacker box.

Stack

PoC

Python script · 1 POST to bypass, 1 to run code

Two-call exploit · simple, repeatable, demo-friendly. Authorisation: defensive research, lab-only.

Demo

Recon → exploit → shell in 4 seconds

Live capture shows how fast a forgotten PaperCut box gets owned · concrete proof for asset-management conversations.

Remediation

Patch path + LAN segmentation note

Upgrade to 20.1.7 / 21.2.11 / 22.0.9+, segment the print LAN, restrict the management UI to ops-only · documented alongside the PoC.

Lessons

Logic flaws beat port-closing

Closing the firewall isn't enough · the SetupCompleted page is reachable behind the firewall too. Auth-bypass at the application layer is the real attack surface.

Fallstudie

“We had a 'firewall closes everything, we're fine' attitude and a print server we'd forgotten existed. The proof-of-concept took four seconds, and showed our security team that someone from outside could take the whole thing over completely. The patch and the network split we'd been arguing about for months happened the next week. Sobering, but exactly what we needed.”

Anonym · SOC-Leitung · Unternehmen (defensives Forschungsmandat) · GB

Mehr Arbeiten

DField Solutions · DField Bt. · dezso@dfieldsolutions.com
5,0
“Von der LinkedIn-Nachricht zur Live-Seite. Zwei winzige Änderungen, dann online.”Michael J Ringer · Vilya ProtectionGründer · Spanien