PT-2023-6281 · Honeywell · Honeywell Pm43

·

CVE-2023-3710

·

Published

2023-09-12

·

Updated

2025-09-12

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Honeywell PM43 versions prior to P10.19.050004
Description The issue is related to an Improper Input Validation vulnerability in the Honeywell PM43 printer's web page modules, allowing Command Injection. This can enable a remote attacker to execute arbitrary commands. Approximately 187 devices may be affected.
Recommendations Update to the latest available firmware version of the respective printers to version MR19.5 (e.g., P10.19.050006). As a temporary workaround, consider restricting access to the vulnerable web page modules until a patch is available.

Exploit

Fix

Command Injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-06991
CVE-2023-3710

Affected Products

Honeywell Pm43