peter bassill · operator
$ cve CVE-2017-5671 JSON

CVE-2017-5671 EXPLOIT

8.8
HIGH · CVSS 3.0 · EPSS 1.4% (pctl 72)

Patch early

A public exploit exists.

Description

Honeywell Intermec PM23, PM42, PM43, PC23, PC43, PD43, and PC42 industrial printers before 10.11.013310 and 10.12.x before 10.12.013309 have /usr/bin/lua installed setuid to the itadmin account, which allows local users to conduct a BusyBox jailbreak attack and obtain root privileges by overwriting the /etc/shadow file.

Scoring

CVSS8.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS1.4% — more likely to be exploited than 72% of all CVEs
WeaknessCWE-269
On CISA KEVno
Public exploityes
Published2017-03-29
Last modified2026-06-17

Affected (14)

VendorProduct
honeywellintermec pc23
honeywellintermec pc23 firmware
honeywellintermec pc42
honeywellintermec pc42 firmware
honeywellintermec pc43
honeywellintermec pc43 firmware
honeywellintermec pd43
honeywellintermec pd43 firmware
honeywellintermec pm23
honeywellintermec pm23 firmware
honeywellintermec pm42
honeywellintermec pm42 firmware
honeywellintermec pm43
honeywellintermec pm43 firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD