New Stormshield SNS protection for CVE-2023-27350 (PaperCut NG)

PaperCut NG is a printing management solution. Some of its version are vulnerable to an authentication bypass. An attacker can leverage this vulnerability to execute arbitrary code in the context of SYSTEM.

The Stormshield Customer Security Lab team has deployed two SNS protection signatures, to detect and block the authentication bypass itself, and the code execution.

IDName
http:mix.348Authentication bypass attempt on PaperCut NG server (CVE-2023-27350)
http:mix.349Exploitation of a RCE vulnerability on Papercut NG server (CVE-2023-27350)