CVE Feed

    Dashboard / CVE / CVE-2017-5671

    CVE-2017-5671

    Honeywell Intermec PM23, PM42, PM43, PC23, PC43, PD43, and PC42 industrial printers before 10.11.013310 and 10.12.x before 10.12.013309 have /usr/bin/lua installed setuid to the itadmin account, which allows local users to conduct a BusyBox jailbreak attack and obtain root privileges by overwriting the /etc/shadow file.

    Published:Mar 29, 2017
    Last Modified:Apr 20, 2025
    EPS:Mar 29, 2017
    EPSS Score:0.00507
    CVSS Score:8.8

    Affected Products

    Vendor
    Honeywell
    Product
    Intermec Pc23
    Vendor
    Honeywell
    Product
    Intermec Pc23 Firmware
    Vendor
    Honeywell
    Product
    Intermec Pc42
    Vendor
    Honeywell
    Product
    Intermec Pc42 Firmware
    Vendor
    Honeywell
    Product
    Intermec Pc43
    Vendor
    Honeywell
    Product
    Intermec Pc43 Firmware
    Vendor
    Honeywell
    Product
    Intermec Pd43
    Vendor
    Honeywell
    Product
    Intermec Pd43 Firmware
    Vendor
    Honeywell
    Product
    Intermec Pm23
    Vendor
    Honeywell
    Product
    Intermec Pm23 Firmware
    Vendor
    Honeywell
    Product
    Intermec Pm42
    Vendor
    Honeywell
    Product
    Intermec Pm42 Firmware
    Vendor
    Honeywell
    Product
    Intermec Pm43
    Vendor
    Honeywell
    Product
    Intermec Pm43 Firmware

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High