← Vulnerability feed

Vulnerability record · CVE-2024-47176 · published 26 September 2024

CVE-2024-47176: cups-browsed binds to all interfaces and trusts any source, enabling remote command execution

Openprinting · Cups Browsed

cups-browsed binds to INADDR_ANY:631 and trusts packets from any source, allowing it to be directed to fetch Get-Printer-Attributes from an attacker-controlled URL. Chained with CVE-2024-47076, CVE-2024-47175 and CVE-2024-47177, this lets an unauthenticated remote attacker execute arbitrary commands when a malicious printer is printed to. The flaw matters because it turns a widely deployed printing daemon into a remote code execution path on exposed hosts.

5.3 CVSS 3.1 Medium EPSS 51% · top 1.1% CWE-1327 · CWE-1327
5.3CVSS 3.1 base score
51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

CUPS is a standards-based, open-source printing system, and `cups-browsed` contains network printing functionality including, but not limited to, auto-discovering print services and shared printers. `cups-browsed` binds to `INADDR_ANY:631`, causing it to trust any packet from any source, and can cause the `Get-Printer-Attributes` IPP request to an attacker controlled URL. When combined with other vulnerabilities, such as CVE-2024-47076, CVE-2024-47175, and CVE-2024-47177, an attacker can execute arbitrary commands remotely on the target machine without authentication when a malicious printer is printed to.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityThe CVE alone scores medium, but it is a key link in a publicly documented unauthenticated remote code execution chain with very high EPSS, so defenders should treat it as high priority.

What it is

cups-browsed binds to INADDR_ANY:631 and trusts packets from any source, allowing it to be directed to fetch Get-Printer-Attributes from an attacker-controlled URL. Chained with CVE-2024-47076, CVE-2024-47175 and CVE-2024-47177, this lets an unauthenticated remote attacker execute arbitrary commands when a malicious printer is printed to. The flaw matters because it turns a widely deployed printing daemon into a remote code execution path on exposed hosts.

Impact

An attacker can cause the target to contact an attacker-controlled IPP service and, in combination with the related flaws, execute arbitrary commands remotely without authentication. The direct CVSS impact for this CVE alone is limited to integrity, but the chained outcome is full remote command execution.

Attack surface

Reached over the network via IPP traffic to port 631; cups-browsed listens on all interfaces and accepts packets from any source. No authentication is required, and the final command execution step requires a user to print to the malicious printer.

Exploitation

Not listed in CISA KEV, but EPSS is high (0.506 probability, 98.9th percentile) and the vendor advisory and third-party writeup are tagged as Exploit, indicating public exploitation detail exists. No ransomware group usage is documented in the record.

What to do

  • Apply the cups-browsed patch referenced in the vendor advisory and commit, and update cups-filters, libcupsfilters and libppd to fixed versions.
  • Disable or remove cups-browsed where network printer auto-discovery is not needed.
  • Restrict access to TCP/UDP port 631 to trusted networks and hosts; do not expose CUPS to the internet.
  • Bind cups-browsed to localhost or specific interfaces instead of INADDR_ANY where operationally possible.
  • Monitor and limit outbound IPP connections from print servers to unexpected external addresses.

Detection

  • Alert on cups-browsed or CUPS processes making outbound connections to external or unexpected IPP endpoints on port 631.
  • Monitor for new printer or PPD entries appearing on hosts, especially those referencing external URLs or unusual attributes.
  • Review CUPS and cups-browsed logs for Get-Printer-Attributes requests to non-local or attacker-controlled addresses.
  • Hunt for command execution or child processes spawned by cups-browsed or the CUPS printing stack outside normal print jobs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-47176 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2024-47176), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.