CVE Database
/

CVE-2023-3711

Back to search

CVE-2023-3711

Published: Sep 12, 2023

Modified: Sep 12, 2025

PUBLISHED

CVSS v3.1

6.4

MEDIUM

Description

Session Fixation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Session Credential Falsification through Prediction.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).

VendorProductVersions

Honeywell

PM23/43

affected
0 - < P10.19.050004

Honeywell

PC23/43, PD43

affected
0 - < K10.19.050004

Honeywell

PM42

affected
0 - < T10.19.050004

Honeywell

PM42

affected
0 - < L10.19.050004

Honeywell

PX4ie/6ie

affected
0 - < A10.19.050004

Honeywell

PX45/65

affected
0 - < B10.19.050004

Honeywell

PD45, PX240

affected
0 - < F10.19.050004

Honeywell

PX940

affected
0 - < H10.19.050004

Honeywell

PM45

affected
0 - < J10.19.050004

Honeywell

RP2f/RP4f

affected
0 - < M10.19.050006

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L

Attack Vector

Network

Attack Complexity

High

Privileges Required

None

User Interaction

Required

Scope

Unchanged

Confidentiality

High

Integrity

Low

Availability

Low

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now