CVE-2023-3710

Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.9 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
honeywellpm23_43
𝑥
< P10.19.050004
ADP
honeywellpc23_43
𝑥
< K10.19.050004
ADP
honeywellpd43
𝑥
< K10.19.050004
ADP
honeywellpm42
𝑥
< T10.19.050004
ADP
honeywellpm42
𝑥
< L10.19.050004
ADP
honeywellpx4ie_6ie
𝑥
< A10.19.050004
ADP
honeywellpx45_65
𝑥
< B10.19.050004
ADP
honeywellpx45
𝑥
< F10.19.050004
ADP
honeywellpx240
𝑥
< F10.19.050004
ADP
honeywellpx940
𝑥
< H10.19.050004
ADP
honeywellpm45
𝑥
< J10.19.050004
ADP
honeywellrp2f_rp4f
𝑥
< M10.19.050006
ADP