CVE-2023-3711

MEDIUM

Honeywell PM43 <P10.19.050004 - Session Fixation

Title source: llm
STIX 2.1

Description

Session Fixation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Session Credential Falsification through Prediction.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).

Scores

CVSS v3 6.4
EPSS 0.0012
EPSS Percentile 30.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-384
Status published
Products (1)
honeywell/pm43_firmware < p10.19.050004
Published Sep 12, 2023
Tracked Since Feb 18, 2026