PT-2023-6281 · Honeywell · Honeywell Pm43
Jinqi Lai
·
Published
2023-09-12
·
Updated
2025-09-12
·
CVE-2023-3710
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Honeywell PM43 versions prior to P10.19.050004
Description
The issue is related to an Improper Input Validation vulnerability in the Honeywell PM43 printer's web page modules, allowing Command Injection. This can enable a remote attacker to execute arbitrary commands. Approximately 187 devices may be affected.
Recommendations
Update to the latest available firmware version of the respective printers to version MR19.5 (e.g., P10.19.050006). As a temporary workaround, consider restricting access to the vulnerable web page modules until a patch is available.
Exploit
Fix
Command Injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Honeywell Pm43