# CVE-2024-1654

## Summary

- **CVE ID:** CVE-2024-1654
- **Severity:** HIGH
- **CVSS Score:** 7.2 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-183
- **Published:** Mar 14, 2024
- **Last Modified:** Mar 13, 2026

## Description

This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker must already have authenticated admin access and knowledge of both an internal system identifier and details of another valid user to exploit this.

## Affected Products

- PaperCut — PaperCut NG, PaperCut MF (0)

## References

- [CNA](https://www.papercut.com/kb/Main/Security-Bulletin-March-2024)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.31%
- **EPSS Percentile:** 68.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._