CVE-2017-12718
A Classic Buffer Overflow issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.8%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
A Classic Buffer Overflow issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. A third-party component used in the pump does not verify input buffer size prior to copying, leading to a buffer overflow, allowing remote code execution on the target device. The pump receives the potentially malicious input infrequently and under certain conditions, increasing the difficulty of exploitation.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 12.78% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120, CWE-119
- Affected
- smiths-medical/medfusion 4000 wireless syringe infusion pump
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/100665Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/101252Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSMA-17-250-02AThird Party Advisory, US Government Resource
- https://www.exploit-db.com/exploits/43776/Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/100665Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/101252Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSMA-17-250-02AThird Party Advisory, US Government Resource
- https://www.exploit-db.com/exploits/43776/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.