CVE-2024-1654
HIGHDescription
This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker must already have authenticated admin access and knowledge of both an internal system identifier and details of another valid user to exploit this.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| papercut | papercut_mf |
| papercut | papercut_mf |
| papercut | papercut_mf |
| papercut | papercut_mf |
| papercut | papercut_ng |
| papercut | papercut_ng |
| papercut | papercut_ng |
| papercut | papercut_ng |
| apple | macos |
| linux | linux_kernel |
| microsoft | windows |
References
Frequently Asked Questions
What is CVE-2024-1654? +
How severe is CVE-2024-1654? +
What products are affected by CVE-2024-1654? +
How do I check if I'm vulnerable to CVE-2024-1654? +
Related Vulnerabilities
NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environment_params() method that allows authenticated users with …
Permissive list of allowed inputs in Microsoft Purview allows an authorized attacker to elevate privileges over a network.
OpenClaw before 2026.3.22 contains an incomplete host environment variable sanitization vulnerability in host-env-security-policy.json and host-env-security.ts that allows package-manager environment overrides. …
In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who …
A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticated (lowprivileged) attacker …