Session Fixation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Session Credential Falsification through Prediction.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printer
Session Fixation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Session Credential Falsification through Prediction.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).
| Vendor | Product | Versions |
|---|---|---|
| Honeywell | PM23/43 | 0 |
| Honeywell | PC23/43, PD43 | 0 |
| Honeywell | PM42 | 0 |
| Honeywell | PM42 | 0 |
| Honeywell | PX4ie/6ie | 0 |
| Honeywell | PX45/65 | 0 |
| Honeywell | PD45, PX240 | 0 |
| Honeywell | PX940 | 0 |
| Honeywell | PM45 | 0 |
| Honeywell | RP2f/RP4f | 0 |
Not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. EPSS is the best forward-looking signal — see the EPSS row above.
For the full vendor write-up, exploit chains, and reference implementations, see the references list in section 09.
Open the Sigma generator with a pre-filled prompt for this CVE to draft a starting detection in your stack of choice:
No directly-cited follow-up CVEs in the KB record for this advisory. The references list in section 09 carries the vendor cross-references.