CVE-2023-3710

Printer web page invalid command execution

Description

Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).

Categories

9.9
CVSS
Severity: Critical
CVSS 3.1 •
EPSS 91.46% Top 5%
Affected: Honeywell PM23/43
Affected: Honeywell PC23/43, PD43
Affected: Honeywell PM42
Affected: Honeywell PM42
Affected: Honeywell PX4ie/6ie
Affected: Honeywell PX45/65
Affected: Honeywell PD45, PX240
Affected: Honeywell PX940
Affected: Honeywell PM45
Affected: Honeywell RP2f/RP4f
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2023-3710?
CVE-2023-3710 has been scored as a critical severity vulnerability.
How to fix CVE-2023-3710?
To fix CVE-2023-3710, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2023-3710 being actively exploited in the wild?
It is possible that CVE-2023-3710 is being exploited or will be exploited in a near future based on public information. According to its EPSS score, there is a ~91% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2023-3710?
CVE-2023-3710 affects Honeywell PM23/43, Honeywell PC23/43, PD43, Honeywell PM42, Honeywell PM42, Honeywell PX4ie/6ie, Honeywell PX45/65, Honeywell PD45, PX240, Honeywell PX940, Honeywell PM45, Honeywell RP2f/RP4f.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.