CVE-2025-9785
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-09-03

Last updated on: 2025-09-04

Assigner: PaperCut

Description
PaperCut Print Deploy is an optional component that integrates with PaperCut NG/MF which simplifies printer deployment and management. When the component is deployed to an environment, the customer has an option to configure the system to use a self-signed certificate. If the customer does not fully configure the system to leverage the trust database on the clients, it opens up the communication between clients and the server to man-in-the-middle attacks.Β  It was discovered that certain parts of the documentation related to the configuration of SSL in Print Deploy were lacking, which could potentially contribute to a misconfiguration of the Print Deploy client installation. PaperCut strongly recommends to use valid certificates to secure installations and to follow the updated documentation to ensure the correct SSL configuration. Those who use private CAs and/or self-signed certificates should make sure to copy their Certification Authority certificate, or their self signed certificate if using only one, to the trust store of their operating system and to the Java key store
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-09-03
Last Modified
2025-09-04
Generated
2026-05-27
AI Q&A
2025-09-03
EPSS Evaluated
2026-05-25
NVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
papercut papercut_ng 4.0
papercut print_deploy 4.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability involves the PaperCut Print Deploy component, which simplifies printer deployment and management. If the system is configured to use a self-signed certificate but the client trust database is not properly configured, it can expose communication between clients and the server to man-in-the-middle attacks. The issue is partly due to incomplete documentation on SSL configuration, which may lead to misconfiguration. Proper use of valid certificates and following updated documentation is strongly recommended to secure installations.


How can this vulnerability impact me? :

If exploited, this vulnerability can allow an attacker to perform man-in-the-middle attacks on the communication between clients and the PaperCut Print Deploy server. This could lead to interception, modification, or theft of sensitive data transmitted during printer deployment and management processes.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, ensure that your PaperCut Print Deploy installation uses valid certificates rather than self-signed certificates. Follow the updated documentation to correctly configure SSL. If you must use private CAs or self-signed certificates, copy the Certification Authority certificate or the self-signed certificate to the trust store of your operating system and to the Java key store to prevent man-in-the-middle attacks.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart