PT-2023-6281 · Honeywell · Honeywell Pm43

Jinqi Lai

·

Published

2023-09-12

·

Updated

2025-09-12

·

CVE-2023-3710

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Honeywell PM43 versions prior to P10.19.050004
Description The issue is related to an Improper Input Validation vulnerability in the Honeywell PM43 printer's web page modules, allowing Command Injection. This can enable a remote attacker to execute arbitrary commands. Approximately 187 devices may be affected.
Recommendations Update to the latest available firmware version of the respective printers to version MR19.5 (e.g., P10.19.050006). As a temporary workaround, consider restricting access to the vulnerable web page modules until a patch is available.

Exploit

Fix

Command Injection

RCE

Weakness Enumeration

Related Identifiers

BDU:2023-06991
CVE-2023-3710

Affected Products

Honeywell Pm43