PT-2023-6281 · Honeywell · Honeywell Pm43
Jinqi Lai
·
Publicado
2023-09-12
·
Atualizado
2025-09-12
·
CVE-2023-3710
CVSS v3.1
9.9
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Honeywell PM43 versions prior to P10.19.050004
Description
The issue is related to an Improper Input Validation vulnerability in the Honeywell PM43 printer's web page modules, allowing Command Injection. This can enable a remote attacker to execute arbitrary commands. Approximately 187 devices may be affected.
Recommendations
Update to the latest available firmware version of the respective printers to version MR19.5 (e.g., P10.19.050006). As a temporary workaround, consider restricting access to the vulnerable web page modules until a patch is available.
Exploit
Correção
Command Injection
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Honeywell Pm43