← All CVEs

CVE-2023-3710

critical · 9.9

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).

9.9
CVSS
49.0%
EPSS (exploit prob.)
99th
EPSS percentile
2023-09-12
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H

Weaknesses

CWE-20CWE-77

Affected products

VendorProductAffected versions
honeywellpm43_firmware< p10.19.050004
honeywellpm43all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-3710