CVE-2023-3710 is a critical improper input validation vulnerability affecting Honeywell PM43 printers running firmware versions prior to P10.19.050004. This flaw allows for unauthenticated remote command injection through the printer's web interface, leading to complete compromise of the device. With a CVSS score of 9.8 (Critical) and an EPSS score indicating high exploitability, this vulnerability poses a significant risk due to its network-based attack vector and low attack complexity. While not currently on the CISA KEV list or actively exploited in the wild, public exploit code and Nuclei templates are available, suggesting a high potential for future exploitation. Organizations are strongly advised to update affected PM43 printers to firmware version MR19.5 (e.g., P10.19.050006) immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< p10.19.050004CPE matchmatch criteria | cpe:2.3:o:honeywell:pm43_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.