logo

CVE-2024-47076, CVE-2024-47175, CVE-2024-47176, CVE-2024-47177: Frequently Asked Questions About Common UNIX Printing System (CUPS) Vulnerabilities

ID: 3e8f7b3d-d154-5666-9c98-45d2770f8235

STIX ID: report--3e8f7b3d-d154-5666-9c98-45d2770f8235

Feed Name: Security Boulevard

Threat Score
70/100

Date Published: 2024-09-26

Date Updated: 2026-04-22

Author: Tenable Security Response Team

...
...

Tenable published an FAQ on multiple CUPS vulnerabilities (four CVEs) disclosed on September 26 that can enable remote code execution when combined (e.g., via a crafted fake printer). The report summarizes technical impacts (input validation flaws, trusting IPP packets, PPD injection, command execution via FoomaticRIPCommandLine), notes available PoCs, recommends immediate mitigations (remove/disable cups-browsed, block UDP port 631), reports significant numbers of internet-exposed CUPS instances, and states no evidence of prior zero-day exploitation at the time of disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.