CVE-2017-5671: High severity Honeywell Intermec Pc23 Firmware vulnerability

Published Mar 29, 2017
·
Updated

Honeywell Intermec PM23, PM42, PM43, PC23, PC43, PD43, and PC42 industrial printers before 10.11.013310 and 10.12.x before 10.12.013309 have /usr/bin/lua installed setuid to the itadmin account, which allows local users to conduct a BusyBox jailbreak attack and obtain root privileges by overwriting the /etc/shadow file.

Affected Software

28 affected components
Honeywell Intermec Pc23 Firmware<=10.10.011406
Honeywell Intermec Pc42 Firmware<=10.10.011406
Honeywell Intermec Pc43 Firmware<=10.10.011406
Honeywell Intermec Pd43 Firmware<=10.10.011406
Honeywell Intermec Pm23 Firmware<=10.10.011406
Honeywell Intermec Pm42 Firmware<=10.10.011406
Honeywell Intermec Pm43 Firmware<=10.10.011406
Honeywell Intermec Pc23
Honeywell Intermec Pc42
Honeywell Intermec Pc43
Honeywell Intermec Pd43
Honeywell Intermec PM23
Honeywell Intermec Pm42
Honeywell Intermec Pm43
All of the following
Any of the following
Honeywell Intermec Pc23 Firmware<=10.10.011406
Honeywell Intermec Pc42 Firmware<=10.10.011406
Honeywell Intermec Pc43 Firmware<=10.10.011406
Honeywell Intermec Pd43 Firmware<=10.10.011406
Honeywell Intermec Pm23 Firmware<=10.10.011406
Honeywell Intermec Pm42 Firmware<=10.10.011406
Honeywell Intermec Pm43 Firmware<=10.10.011406
Any of the following
Honeywell Intermec Pc23
Honeywell Intermec Pc42
Honeywell Intermec Pc43
Honeywell Intermec Pd43
Honeywell Intermec PM23
Honeywell Intermec Pm42
Honeywell Intermec Pm43

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Honeywell Intermec industrial printers (PM23, PM42, PM43, PC23, PC43, PD43, PC42) to a version that resolves this vulnerability.

    Fixed in 10.11.013310
  2. Upgrade

    Upgrade Honeywell Intermec industrial printers (PM23, PM42, PM43, PC23, PC43, PD43, PC42) to a version that resolves this vulnerability.

    Fixed in 10.12.013309
  3. Compensating control

    Mitigate the BusyBox jailbreak/root escalation by removing or disabling the setuid installation of /usr/bin/lua (currently installed setuid to the itadmin account on affected versions) so local users cannot use it to obtain root privileges and overwrite /etc/shadow.

Event History

Mar 29, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2017-5671?

CVE-2017-5671 has a high severity rating due to its potential to allow local users to gain root privileges.

2

How do I fix CVE-2017-5671?

To fix CVE-2017-5671, update the Honeywell Intermec printers to firmware version 10.11.013310 or higher.

3

Which devices are affected by CVE-2017-5671?

CVE-2017-5671 affects the Honeywell Intermec PM23, PM42, PM43, PC23, PC43, PD43, and PC42 industrial printers with versions before 10.11.013310.

4

What attack can be conducted due to CVE-2017-5671?

CVE-2017-5671 allows local users to conduct a BusyBox jailbreak attack to obtain root privileges on the affected printers.

5

Is there a known workaround for CVE-2017-5671?

There are no known workarounds for CVE-2017-5671; the recommended action is to upgrade the firmware.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203