← Global Threat Landscape
CVE-2023-27351
CWE-287
High
89.8
RPSRPS range: 0–105; KEV-listed vulnerabilities can receive an exploitation amplifier.
Description
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results from improper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-19226.
Source: NVD
Signals
- CVSS
- 7.5
- High · v3.1
- EPSS
- 78.05%
- Probability of exploitation in the next 30 days (FIRST)
- CISA KEV
- In CISA KEV since Apr 2026
- Fix commit
- No known fix commit
- Sources: MoreFixes, FreshFixes
- Weakness
- CWE-287
- Published
- 20 Apr 2023
- Last modified 1 Oct 2026
How to read these signals: RPS · EPSS · CISA KEV · Data sources
Get this score from the API
curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
https://api.intelligence.devsecure.io/api/v1/rps/CVE-2023-27351Replace the placeholder with your key. Get a free API key or rank your own CVEs.
Data as of 7 Oct 2026, 05:16 UK time