PaperCut Issues Security Alert and Patch

On August 27th, PaperCut, which markets PaperCut software for tracking, controlling, and securing print and copy jobs, issued a security alert.

The company reported that its security response team has been investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF.

It said it’s aware of confirmed customer security incidents and is treating this matter with the highest priority. 

Action Required

PaperCut said that if a customer’s PaperCut NG/MF Application Server is accessible from the public Internet, they should immediately restrict Web access to trusted IP addresses only, such as internal IP addresses.

Customers should also use firewall rules, network access controls, or equivalent measures to ensure the PaperCut server’s Web interfaces can’t be reached from untrusted Internet addresses. Customers should do this now, even if they haven’t observed suspicious activity.

Emergency Patch Release 2

PaperCut also released an emergency patch for customers with public-facing PaperCut NG/MF servers that are unable to take other mitigating action.

It also released an updated emergency patch release on August 28th that includes additional hardening beyond the original emergency patch. It recommends all customers install Release 2, even if they have already applied the original emergency patch.

Download and follow the standard upgrade procedure.

On August 31st, PaperCut reported that it had no new information to report. It said its teams continue to work towards an official release, and remain available for any questions via support.papercut.com.

Visit PaperCut here for more information on the emergency patch.