logo

Critical Unauthenticated RCE Flaws in CUPS Printing Systems

ID: 545511bc-9b3e-585d-b37d-a307e8dd0070

STIX ID: report--545511bc-9b3e-585d-b37d-a307e8dd0070

Feed Name: Qualys Blog

Threat Score
90/100

Date Published: 2024-09-26

Date Updated: 2026-04-28

Author: Saeed Abbasi

...
...

This advisory describes multiple critical unauthenticated RCE vulnerabilities in the CUPS printing system (CVE-2024-47176, CVE-2024-47076, CVE-2024-47175, CVE-2024-47177) with a reported CVSS of 9.9, explains how attackers can send malicious UDP/IP P packets or serve malicious PPD directives to achieve remote code execution, estimates >75k publicly exposed assets (≈42k accepting unauthenticated connections), and provides mitigations (disable cups-browsed, firewall UDP port 631, restrict mDNS/DNS-SD, and apply vendor patches/QIDs when available).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.