RULE(RULE ID:337815)

Rule General Information
Release Date: 2024-02-20
Rule Name: Honeywell PM43 Username Command Injection Vulnerablity Vulnerability (CVE-2023-3710)
Severity:
CVE ID:
Rule Protection Details
Description: Honeywell Products is a series of products from Honeywell Corporation in the United States. Honeywell PM43 P10.19.050004 and earlier versions have a command injection vulnerability due to severe insufficient input of parameters. Attackers can exploit this vulnerability to execute malicious commands, gain unauthorized access, steal sensitive data, and cause system damage.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: https://hsmftp.honeywell.com
https://hsmftp.honeywell.com
https://www.honeywell.com/us/en/product-security
https://nvd.nist.gov/vuln/detail/CVE-2023-3710
Solutions
Refer to the announcement or patch by the vendor: https://hsmftp.honeywell.com/en/Software/Printers/Industrial/PM23-PM23c-PM43-PM43c/Current/Firmware/firmwaresignedP1019050004