CVE-2024-47176General(openprinting / cups-browsed)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

CUPS is a standards-based, open-source printing system, and `cups-browsed` contains network printing functionality including, but not limited to, auto-discovering print services and shared printers. `cups-browsed` binds to `INADDR_ANY:631`, causing it to trust any packet from any source, and can cause the `Get-Printer-Attributes` IPP request to an attacker controlled URL. When combined with other vulnerabilities, such as CVE-2024-47076, CVE-2024-47175, and CVE-2024-47177, an attacker can execute arbitrary commands remotely on the target machine without authentication when a malicious printer is printed to.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1327

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cups-browsed

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-15); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
cups-browsed

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-15: 1Mentions · 2026-09-28: 102-1509-28
Signal classification1 categories
General
1100.0%
Referenced assets1 URL
Full discourse2 posts
  • SHELLCODE@sh3ll_c0d3

    🔥 LINUX CUPS 4-CVE RCE CHAIN: Zero-Click Root Takeover! 🖨️🐧 Single spoofed UDP packet to port 631 triggers remote root shell execution via cups-browsed & foomatic-rip. 👉 Analysis: https://sh3llc0d3.com/blog/linux-cups-4-cve-remote-code-execution-chain-how-cups-browsed-udp-631-and-foomatic-rip-enable-zero-interaction-root-compromise-cve-2024-47176-cve-2024-47076-cve-2024-47175-cve-2024-47177/ #sh3llc0d3 #shellcode #Linux #CUPS #RCE

    0001051
    108 followersView on X
  • Jon@telep_io
    General

    How have we never removed CUPS (Commun Unix Printing System) from being included by default on Ubuntu images. "It's just leftover" even after 2024 CVE-2024-47176 https://t.co/XHAEevc2Db

    Post summary

    The tweet references CVE‑2024‑47176 but only comments on CUPS remaining on Ubuntu images; it provides no exploit, patch, or technical details.

    00010122
    408 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenprintingcups-browsed2.0.1--

Explore more