PT-2023-6281 · Honeywell · Honeywell Pm43

Jinqi Lai

·

Publicado

2023-09-12

·

Atualizado

2025-09-12

·

CVE-2023-3710

CVSS v3.1

9.9

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Honeywell PM43 versions prior to P10.19.050004
Description The issue is related to an Improper Input Validation vulnerability in the Honeywell PM43 printer's web page modules, allowing Command Injection. This can enable a remote attacker to execute arbitrary commands. Approximately 187 devices may be affected.
Recommendations Update to the latest available firmware version of the respective printers to version MR19.5 (e.g., P10.19.050006). As a temporary workaround, consider restricting access to the vulnerable web page modules until a patch is available.

Exploit

Correção

Command Injection

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-06991
CVE-2023-3710

Produtos afetados

Honeywell Pm43