CVE-2017-5671: High severity Honeywell Intermec Pc23 Firmware vulnerability
Honeywell Intermec PM23, PM42, PM43, PC23, PC43, PD43, and PC42 industrial printers before 10.11.013310 and 10.12.x before 10.12.013309 have /usr/bin/lua installed setuid to the itadmin account, which allows local users to conduct a BusyBox jailbreak attack and obtain root privileges by overwriting the /etc/shadow file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Honeywell Intermec industrial printers (PM23, PM42, PM43, PC23, PC43, PD43, PC42)to a version that resolves this vulnerability.Fixed in 10.11.013310 - Upgrade
Upgrade
Honeywell Intermec industrial printers (PM23, PM42, PM43, PC23, PC43, PD43, PC42)to a version that resolves this vulnerability.Fixed in 10.12.013309 - Compensating control
Mitigate the BusyBox jailbreak/root escalation by removing or disabling the setuid installation of /usr/bin/lua (currently installed setuid to the itadmin account on affected versions) so local users cannot use it to obtain root privileges and overwrite /etc/shadow.
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5671?
CVE-2017-5671 has a high severity rating due to its potential to allow local users to gain root privileges.
How do I fix CVE-2017-5671?
To fix CVE-2017-5671, update the Honeywell Intermec printers to firmware version 10.11.013310 or higher.
Which devices are affected by CVE-2017-5671?
CVE-2017-5671 affects the Honeywell Intermec PM23, PM42, PM43, PC23, PC43, PD43, and PC42 industrial printers with versions before 10.11.013310.
What attack can be conducted due to CVE-2017-5671?
CVE-2017-5671 allows local users to conduct a BusyBox jailbreak attack to obtain root privileges on the affected printers.
Is there a known workaround for CVE-2017-5671?
There are no known workarounds for CVE-2017-5671; the recommended action is to upgrade the firmware.