CUPS is a standards-based, open-source printing system, and cups-browsed contains network printing functionality including, but not limited to, auto-discovering print services and shared printers. cups-browsed binds to INADDR_ANY:631, causing it to trust any packet from any source, and can cause the Get-Printer-Attributes IPP request to an attacker controlled URL. When combined with other vulnerabilities, such as CVE-2024-47076, CVE-2024-47175, and CVE-2024-47177, an attacker can execute arbitrary commands remotely on the target machine without authentication when a malicious printer is printed to.
CVE-2024-47176
Score elevated to 9.0 because EPSS predicts 87% probability of exploitation within the next 30 days (top 0.5% of all CVEs). NVD baseline CVSS 5.3 retained for reference. Confidence: see factors.
- High exploitation likelihood — EPSS 50%
A fix is available — apply it.
- CVSS v3
- 5.3
- EG Score
- 9.0(high)
- EG Risk
- —
- EPSS
- 98.8%
- KEV
- Not listed
Published
September 26, 2024
Last Modified
November 4, 2025
References (12)
- security-advisories@githubhttps://github.com/OpenPrinting/cups-browsed/blob/master/daemon/cups-browsed.c#L13992
- security-advisories@githubhttps://github.com/OpenPrinting/cups-browsed/security/advisories/GHSA-rj88-6mr5-rcw8
- security-advisories@githubhttps://github.com/OpenPrinting/cups-filters/security/advisories/GHSA-p9rh-jxmq-gq47
- security-advisories@githubhttps://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-w63j-6g73-wmg5
- security-advisories@githubhttps://github.com/OpenPrinting/libppd/security/advisories/GHSA-7xfx-47qg-grp6
- security-advisories@githubhttps://www.cups.org
- security-advisories@githubhttps://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I
- af854a3a-2127-422b-91ae-364da2661108http://www.openwall.com/lists/oss-security/2024/09/27/6
- af854a3a-2127-422b-91ae-364da2661108http://www.openwall.com/lists/oss-security/2025/09/11/2
- af854a3a-2127-422b-91ae-364da2661108https://github.com/OpenPrinting/cups-browsed/commit/1debe6b140c37e0aa928559add4abcc95ce54aa2
- af854a3a-2127-422b-91ae-364da2661108https://lists.debian.org/debian-lts-announce/2024/09/msg00048.html
- af854a3a-2127-422b-91ae-364da2661108https://security.netapp.com/advisory/ntap-20241011-0001/
Patch Availability(17)
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
All Vendor Advisories
(17)
Every vendor that published an advisory referencing this CVE — pulled from our cve_vendor_advisories aggregation. Click any row for the vendor's original advisory page.
- Red HatRHSA-2024:7346IMPORTANT2024-09-26
RHSA-2024:7346 — Important
- Red HatRHSA-2024:7461IMPORTANT2024-09-26
RHSA-2024:7461 — Important
- Red HatRHSA-2024:7462IMPORTANT2024-09-26
RHSA-2024:7462 — Important
- Red HatRHSA-2024:7463IMPORTANT2024-09-26
RHSA-2024:7463 — Important
- Red HatRHSA-2024:7503IMPORTANT2024-09-26
RHSA-2024:7503 — Important
- Red HatRHSA-2024:7504IMPORTANT2024-09-26
RHSA-2024:7504 — Important
- Red HatRHSA-2024:7506IMPORTANT2024-09-26
RHSA-2024:7506 — Important
- Red HatRHSA-2024:7551IMPORTANT2024-09-26
RHSA-2024:7551 — Important
- Red HatRHSA-2024:7553IMPORTANT2024-09-26
RHSA-2024:7553 — Important
- Red HatRHSA-2024:7623IMPORTANT2024-09-26
RHSA-2024:7623 — Important
- UbuntuUSN-7042-1MEDIUM
cups-browsed vulnerability
- UbuntuUSN-7042-2MEDIUM
cups-browsed vulnerability
- UbuntuUSN-7042-3MEDIUM
cups-browsed vulnerability
- UbuntuUSN-7043-1MEDIUM
cups-filters vulnerabilities
- UbuntuUSN-7043-2MEDIUM
cups-filters vulnerability
- UbuntuUSN-7043-3MEDIUM
cups-filters vulnerability
- UbuntuUSN-7043-4MEDIUM
cups-filters vulnerabilities
Data Freshness Timeline
(refreshed 7× in last 7d / 29× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-07-22 14:07 UTCEPSS rescore
- 2026-07-22 14:07 UTCEPSS rescore
- 2026-07-21 15:23 UTCEPSS rescore
- 2026-07-20 17:06 UTCEPSS rescore
- 2026-07-18 10:03 UTCEPSS rescore
- 2026-07-18 10:03 UTCEPSS rescore
- 2026-07-16 17:02 UTCEPSS rescore
- 2026-07-15 16:57 UTCEPSS rescore
- 2026-07-15 16:56 UTCEPSS rescore
- 2026-07-15 01:59 UTCEPSS rescore
- 2026-07-15 01:59 UTCEPSS rescore
- 2026-07-14 00:38 UTCOSV refresh
- 2026-07-13 06:12 UTCEPSS rescore
- 2026-07-12 05:45 UTCEPSS rescore
- 2026-07-12 05:45 UTCEPSS rescore
- 2026-07-11 08:26 UTCEPSS rescore
- 2026-07-09 19:09 UTCEPSS rescore
- 2026-07-09 19:09 UTCEPSS rescore
- 2026-07-08 15:14 UTCEPSS rescore
- 2026-07-04 06:30 UTCEPSS rescore
- 2026-07-01 15:05 UTCEPSS rescore
- 2026-06-28 04:55 UTCEPSS rescore
- 2026-06-28 04:55 UTCEPSS rescore
- 2026-06-27 03:07 UTCEPSS rescore
- 2026-06-27 03:07 UTCEPSS rescore
Show 43 moreShow fewer
- 2026-06-25 22:16 UTCOSV refresh
- 2026-06-25 13:49 UTCEPSS rescore
- 2026-06-23 21:32 UTCEPSS rescore
- 2026-06-23 21:32 UTCEPSS rescore
- 2026-06-22 14:25 UTCEPSS rescore
- 2026-06-22 14:25 UTCEPSS rescore
- 2026-06-21 01:59 UTCEPSS rescore
- 2026-06-21 01:58 UTCEPSS rescore
- 2026-06-18 17:52 UTCEPSS rescore
- 2026-06-18 17:52 UTCEPSS rescore
- 2026-06-17 17:52 UTCEPSS rescore
- 2026-06-17 17:52 UTCEPSS rescore
- 2026-06-16 17:52 UTCEPSS rescore
- 2026-06-16 17:52 UTCEPSS rescore
- 2026-06-15 17:47 UTCEPSS rescore
- 2026-06-14 23:17 UTCEPSS rescore
- 2026-06-12 23:11 UTCEPSS rescore
- 2026-06-12 23:11 UTCEPSS rescore
- 2026-06-10 22:18 UTCEPSS rescore
- 2026-06-10 13:21 UTCEPSS rescore
- 2026-06-08 14:16 UTCEPSS rescore
- 2026-06-08 14:16 UTCEPSS rescore
- 2026-06-08 11:44 UTCOSV refresh
- 2026-06-07 15:24 UTCEPSS rescore
- 2026-06-07 15:24 UTCEPSS rescore
- 2026-06-05 22:46 UTCEPSS rescore
- 2026-06-05 22:46 UTCEPSS rescore
- 2026-06-05 06:09 UTCEPSS rescore
- 2026-06-05 06:09 UTCEPSS rescore
- 2026-06-04 13:11 UTCEPSS rescore
- 2026-06-04 13:11 UTCEPSS rescore
- 2026-06-02 20:12 UTCEPSS rescore
- 2026-06-02 20:12 UTCEPSS rescore
- 2026-06-01 13:51 UTCEPSS rescore
- 2026-06-01 13:51 UTCEPSS rescore
- 2026-05-31 22:30 UTCEPSS rescore
- 2026-05-31 22:30 UTCEPSS rescore
- 2026-05-28 13:44 UTCEPSS rescore
- 2026-05-28 13:44 UTCEPSS rescore
- 2026-05-27 13:40 UTCEPSS rescore
- 2026-05-27 13:40 UTCEPSS rescore
- 2026-05-23 21:31 UTCEG score recompute
- 2026-05-23 21:31 UTCVendor advisory
Publicly available exploits
(9 references)Working exploit code is in the public domain (2 Metasploit modules) (6 GitHub PoCs). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoCMalwareTech/CVE-2024-47176-ScannerFirst seen Oct 7, 2024
A simple scanner for identifying vulnerable cups-browsed instances on your network
Open source ↗ - GitHub PoCl0n3m4n/CVE-2024-47176First seen Oct 3, 2024
Unauthenticated RCE on cups-browsed (exploit and nuclei template)
Open source ↗ - GitHub PoClkarlslund/jugularFirst seen Sep 29, 2024
Ultrafast CUPS-browsed scanner (CVE-2024-47176)
Open source ↗ - GitHub PoCaytackalinci/CVE-2024-47176First seen Sep 28, 2024
Vulnerability Scanner for CUPS: CVE-2024-47176
Open source ↗ - GitHub PoCmr-r3b00t/CVE-2024-47176First seen Sep 28, 2024
Scanner
Open source ↗ - GitHub PoCGO0dspeed/spillFirst seen Sep 27, 2024
POC scanner for CVE-2024-47176
Open source ↗ - Metasploitexploit/multi/misc/cups_ipp_remote_code_execution✓ verifiedFirst seen Sep 26, 2024
CUPS IPP Attributes LAN Remote Code Execution
Open source ↗ - Metasploitauxiliary/scanner/misc/cups_browsed_info_disclosure✓ verifiedFirst seen Jan 1, 2024
cups-browsed Information Disclosure
Open source ↗ - Nucleijavascript/cves/2024/CVE-2024-47176.yamlFirst seen Jan 1, 2024
CUPS - Remote Code Execution
Open source ↗
Frequently asked(5)
What is CVE-2024-47176?
When was CVE-2024-47176 disclosed?
Is CVE-2024-47176 actively exploited?
What is the CVSS score of CVE-2024-47176?
How do I remediate CVE-2024-47176?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2024-47176
Is Your Infrastructure Affected by CVE-2024-47176?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.