CVE-2023-3710

Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004.Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).

Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.9 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
HoneywellCNA
9.9 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
honeywellpm23_43
𝑥
< P10.19.050004
honeywellpc23_43
𝑥
< K10.19.050004
honeywellpd43
𝑥
< K10.19.050004
honeywellpm42
𝑥
< T10.19.050004
honeywellpm42
𝑥
< L10.19.050004
honeywellpx4ie_6ie
𝑥
< A10.19.050004
honeywellpx45_65
𝑥
< B10.19.050004
honeywellpx45
𝑥
< F10.19.050004
honeywellpx240
𝑥
< F10.19.050004
honeywellpx940
𝑥
< H10.19.050004
honeywellpm45
𝑥
< J10.19.050004
honeywellrp2f_rp4f
𝑥
< M10.19.050006
𝑥
= Vulnerable software versions