Honeywell PM43 Industrial Printers Files or Directories Accessible to External Parties (CVE-2023-3712)

high Tenable OT Security Plugin ID 504852

Synopsis

The remote OT asset is affected by a vulnerability.

Description

Files or Directories Accessible to External Parties vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Privilege Escalation. This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).

Solution

Refer to the vendor advisory.

See Also

https://nvd.nist.gov/vuln/detail/CVE-2023-3712

http://www.nessus.org/u?78fcebd7

http://www.nessus.org/u?893c9ddb

https://www.honeywell.com/us/en/product-security

Plugin Details

Severity: High

ID: 504852

File Name: tenable_ot_honeywell_CVE-2023-3712.nasl

Version: 1.3

Type: remote

Family: Tenable.ot

Published: 12/16/2025

Updated: 2/23/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2023-3712

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:honeywell:pm43_firmware

Required KB Items: Tenable.ot/Honeywell

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 12/9/2023

Reference Information

CVE: CVE-2023-3712

CWE: 552