First published: Wed Mar 29 2017(Updated: )
Honeywell Intermec PM23, PM42, PM43, PC23, PC43, PD43, and PC42 industrial printers before 10.11.013310 and 10.12.x before 10.12.013309 have /usr/bin/lua installed setuid to the itadmin account, which allows local users to conduct a BusyBox jailbreak attack and obtain root privileges by overwriting the /etc/shadow file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Honeywell Intermec Pc23 Firmware | <=10.10.011406 | |
Honeywell Intermec Pc42 Firmware | <=10.10.011406 | |
Honeywell Intermec Pc43 Firmware | <=10.10.011406 | |
Honeywell Intermec Pd43 Firmware | <=10.10.011406 | |
Honeywell Intermec Pm23 Firmware | <=10.10.011406 | |
Honeywell Intermec Pm42 Firmware | <=10.10.011406 | |
Honeywell Intermec Pm43 Firmware | <=10.10.011406 | |
Honeywell Intermec Pc23 | ||
Honeywell Intermec Pc42 | ||
Honeywell Intermec Pc43 | ||
Honeywell Intermec Pd43 | ||
Honeywell Intermec PM23 | ||
Honeywell Intermec Pm42 | ||
Honeywell Intermec Pm43 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.