CVE-2017-5671 is a local privilege escalation vulnerability affecting several Honeywell Intermec industrial printers, including the PM23, PM42, PM43, PC23, PC43, PD43, and PC42 models running specific firmware versions. The vulnerability stems from the /usr/bin/lua binary being installed setuid to the itadmin account, allowing a local attacker to perform a BusyBox jailbreak. This enables the attacker to overwrite the /etc/shadow file, thereby gaining root privileges on the device. With a CVSS score of 8.8 (High), this vulnerability presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. An attacker with local access can easily achieve full control over the affected printer. Despite its severity, the vulnerability is not listed on CISA's KEV catalog, suggesting it's not widely exploited in the wild. While there is no evidence of active exploitation or Metasploit/Nuclei modules, an exploit (EDB-41754) is publicly available on ExploitDB. Community discussion and media coverage are minimal, indicating a lack of widespread public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.10.011406CPE matchmatch criteria | cpe:2.3:o:honeywell:intermec_pc23_firmware:*:*:*:*:*:*:*:* | ||
<= 10.10.011406CPE matchmatch criteria | cpe:2.3:o:honeywell:intermec_pc42_firmware:*:*:*:*:*:*:*:* | ||
<= 10.10.011406CPE matchmatch criteria | cpe:2.3:o:honeywell:intermec_pc43_firmware:*:*:*:*:*:*:*:* | ||
<= 10.10.011406CPE matchmatch criteria | cpe:2.3:o:honeywell:intermec_pd43_firmware:*:*:*:*:*:*:*:* | ||
<= 10.10.011406CPE matchmatch criteria | cpe:2.3:o:honeywell:intermec_pm23_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.