SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-3710

Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004.

CRITICAL 9.8EPSS 33.1%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 33.1%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
33.09% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-20, CWE-77
Affected
honeywell/pm43 firmware
Source
psirt@honeywell.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.