peter bassill · operator
$ cve CVE-2023-3710 JSON

CVE-2023-3710 EXPLOIT

9.9
CRITICAL · CVSS 3.1 · EPSS 49% (pctl 99)

Patch early

A public exploit exists.

Description

Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).

Scoring

CVSS9.9 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
EPSS49.04% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2023-09-12
Last modified2026-06-17

Affected (2)

VendorProduct
honeywellpm43
honeywellpm43 firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD