Skip to main content

CVE-2024-1222

8.6
HIGHCVSS v3.1 Base Score
2.23%
LOW RiskEPSS (85th percentile)

This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This applies to a small subset of PaperCut NG/MF API calls.

Published: 3/14/2024
Modified: 1/23/2025
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.6HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

EPSS Score (Exploitation Probability)

2.23%LOW Exploitation Risk
85th percentile

This vulnerability has a 2.23% probability of being exploited in the next 30 days, ranking higher than 85% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-250)

CVE-2025-40602MEDIUM 6.6

A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).

12/18/2025
CVE-2025-34515CRITICAL 9.8

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in sync_project.sh that allows an attacker to escalate privileges to root. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.

10/16/2025
CVE-2025-61958HIGH 8.7

A vulnerability exists in the iHealth command that may allow an authenticated attacker with at least a resource administrator role to bypass tmsh restrictions and gain access to a bash shell.  For BIG-IP systems running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

10/15/2025
CVE-2025-59481HIGH 8.7

A vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with at least resource administrator role to execute arbitrary system commands with higher privileges.  A successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

10/15/2025
CVE-2024-38813HIGH 7.5

The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.

9/17/2024

Similar SeverityHIGH