Back to overview

CVE-2023-3710

CRITICAL
9.9
CVSS 3.1
Description
Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).

Metadata

CVE ID
CVE-2023-3710
State
PUBLISHED
Assigner
Honeywell
Reserved
2023-07-17 13:59 UTC
Published
2023-09-12 19:55 UTC
Last updated
2025-09-12 19:31 UTC
Primary CWE
CWE-20
CWE-20 Improper Input Validation
Vendor / Product
Honeywell / PM23/43
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
partial
Affected products (10)
VendorProductPlatformVersions
Honeywell PC23/43, PD43 32 bit 0 < K10.19.050004
Honeywell PD45, PX240 32 bit 0 < F10.19.050004
Honeywell PM23/43 32 bit 0 < P10.19.050004
Honeywell PM42 32 bit 0 < T10.19.050004
Honeywell PM42 32 bit 0 < L10.19.050004
Honeywell PM45 32 bit 0 < J10.19.050004
Honeywell PX45/65 32 bit 0 < B10.19.050004
Honeywell PX4ie/6ie 32 bit 0 < A10.19.050004
Honeywell PX940 32 bit 0 < H10.19.050004
Honeywell RP2f/RP4f 32 bit 0 < M10.19.050006
Weakness (CWE)
CWESourceDescription
CWE-20 cna CWE-20 Improper Input Validation
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
Back to overview