Vulnerability record · CVE-2024-47176 · published 26 September 2024
CVE-2024-47176: cups-browsed binds to all interfaces and trusts any source, enabling remote command execution
Openprinting · Cups Browsed
cups-browsed binds to INADDR_ANY:631 and trusts packets from any source, allowing it to be directed to fetch Get-Printer-Attributes from an attacker-controlled URL. Chained with CVE-2024-47076, CVE-2024-47175 and CVE-2024-47177, this lets an unauthenticated remote attacker execute arbitrary commands when a malicious printer is printed to. The flaw matters because it turns a widely deployed printing daemon into a remote code execution path on exposed hosts.
Description
CUPS is a standards-based, open-source printing system, and `cups-browsed` contains network printing functionality including, but not limited to, auto-discovering print services and shared printers. `cups-browsed` binds to `INADDR_ANY:631`, causing it to trust any packet from any source, and can cause the `Get-Printer-Attributes` IPP request to an attacker controlled URL. When combined with other vulnerabilities, such as CVE-2024-47076, CVE-2024-47175, and CVE-2024-47177, an attacker can execute arbitrary commands remotely on the target machine without authentication when a malicious printer is printed to.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Automated analysis
high priorityThe CVE alone scores medium, but it is a key link in a publicly documented unauthenticated remote code execution chain with very high EPSS, so defenders should treat it as high priority.
What it is
cups-browsed binds to INADDR_ANY:631 and trusts packets from any source, allowing it to be directed to fetch Get-Printer-Attributes from an attacker-controlled URL. Chained with CVE-2024-47076, CVE-2024-47175 and CVE-2024-47177, this lets an unauthenticated remote attacker execute arbitrary commands when a malicious printer is printed to. The flaw matters because it turns a widely deployed printing daemon into a remote code execution path on exposed hosts.
Impact
An attacker can cause the target to contact an attacker-controlled IPP service and, in combination with the related flaws, execute arbitrary commands remotely without authentication. The direct CVSS impact for this CVE alone is limited to integrity, but the chained outcome is full remote command execution.
Attack surface
Reached over the network via IPP traffic to port 631; cups-browsed listens on all interfaces and accepts packets from any source. No authentication is required, and the final command execution step requires a user to print to the malicious printer.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.506 probability, 98.9th percentile) and the vendor advisory and third-party writeup are tagged as Exploit, indicating public exploitation detail exists. No ransomware group usage is documented in the record.
What to do
- Apply the cups-browsed patch referenced in the vendor advisory and commit, and update cups-filters, libcupsfilters and libppd to fixed versions.
- Disable or remove cups-browsed where network printer auto-discovery is not needed.
- Restrict access to TCP/UDP port 631 to trusted networks and hosts; do not expose CUPS to the internet.
- Bind cups-browsed to localhost or specific interfaces instead of INADDR_ANY where operationally possible.
- Monitor and limit outbound IPP connections from print servers to unexpected external addresses.
Detection
- Alert on cups-browsed or CUPS processes making outbound connections to external or unexpected IPP endpoints on port 631.
- Monitor for new printer or PPD entries appearing on hosts, especially those referencing external URLs or unusual attributes.
- Review CUPS and cups-browsed logs for Get-Printer-Attributes requests to non-local or attacker-controlled addresses.
- Hunt for command execution or child processes spawned by cups-browsed or the CUPS printing stack outside normal print jobs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-47176 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2024-47176), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.