GobyVuls/Honeywell_PM43_loadfile.lp_file_command_execution_vulnerability.md

1.2 KiB
Raw Permalink Blame History

Honeywell PM43 loadfile.lp file command execution vulnerability (CVE-2023-3710)

Vulnerability Honeywell PM43 loadfile.lp file command execution vulnerability (CVE-2023-3710)
Chinese name Honeywell PM43 loadfile.lp 文件命令执行漏洞CVE-2023-3710
CVSS core 9.8
FOFA Query (click to view the results directly) app="Honeywell PM43 "
Number of assets affected 96
Description The Honeywell PM43 is a printer product of the American company Honeywell.Honeywell PM43P10.19.050004 and earlier versions of the input verification error vulnerability, attackers can arbitrarily execute code on the server side, write a backdoor, obtain server permissions, and then control the entire web server.
Impact Honeywell PM43P10.19.050004 and earlier versions of the input verification error vulnerability, attackers can arbitrarily execute code on the server side, write a backdoor, obtain server permissions, and then control the entire web server.