vendor:
PM43 Printers
by:
ByteHunter
8.1
CVSS
CRITICAL
Remote Code Execution (RCE)
78
CWE
Product Name: PM43 Printers
Affected Version From: Prior to P10.19.050004
Affected Version To: Not specified
Patch Exists: YES
Related CWE: CVE-2023-3710
CPE: h:honeywell:pm43_firmware
Platforms Tested: Not specified
Not specified
Honeywell PM43 Command Injection Remote Code Execution (RCE)
The exploit allows an attacker to remotely execute arbitrary code on Honeywell PM43 printers with firmware versions prior to P10.19.050004. By sending a crafted payload to the 'loadfile.lp?pageid=Configure' endpoint, an attacker can inject malicious commands. This vulnerability is identified as CVE-2023-3710.
Mitigation:
To mitigate this vulnerability, it is recommended to update the firmware to version P10.19.050004 or later. Additionally, restrict network access to the printer and avoid exposing it directly to the internet.