Vulnerability record · CVE-2023-3710 · published 12 September 2023
CVE-2023-3710: Honeywell PM43 printer web module command injection
Honeywell · Pm43 Firmware
Honeywell PM43 printers running firmware prior to P10.19.050004 contain an improper input validation flaw in the printer web page modules that permits command injection. Because the vulnerable component is reachable over the network without credentials, an unauthenticated attacker can execute commands on the device.
Description
Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, and no user interaction, combined with a high EPSS score, makes this a critical exposure for any unpatched PM43 printer.
What it is
Honeywell PM43 printers running firmware prior to P10.19.050004 contain an improper input validation flaw in the printer web page modules that permits command injection. Because the vulnerable component is reachable over the network without credentials, an unauthenticated attacker can execute commands on the device.
Impact
An attacker gains arbitrary command execution on the printer, which can lead to full device compromise, configuration changes, or use of the printer as a foothold into the network.
Attack surface
The flaw is in the printer web page modules and is reachable over the network (AV:N) with no authentication (PR:N) and no user interaction (UI:N). Any host that can reach the printer's web interface can attempt exploitation.
Exploitation
CVE-2023-3710 is not listed in CISA KEV and no ransomware groups are documented using it, but EPSS is high at roughly 0.49 (98.8th percentile), indicating elevated likelihood of attempted exploitation. Reference tags only point to firmware downloads and vendor product security pages, so no public exploit code is confirmed by this record.
What to do
- Update PM43 firmware to MR19.5 (P10.19.050006) or later as directed by Honeywell.
- If immediate patching is not possible, restrict network access to the printer web interface to trusted management hosts only.
- Place printers on a segmented VLAN isolated from user and server networks.
- Disable or block the printer web interface where it is not operationally required.
- Monitor vendor advisories for further firmware updates.
Detection
- Review printer and web server logs for unusual HTTP requests to the PM43 web interface, especially parameters containing shell metacharacters.
- Alert on unexpected outbound connections or process activity originating from printer IP addresses.
- Baseline printer firmware versions and flag any PM43 device still below P10.19.050004.
- Monitor for authentication-free access to printer web pages from hosts outside the management network.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-3710 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-3710), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.