VulnerabilityModified
CVE-2017-12723
The pump stores some passwords in the configuration file, which are accessible if the pump is configured to allow external communications.
LOW 3.7EPSS 0.97%
Does this matter?
Lower severity and a low EPSS score (0.97%). Track it; it rarely justifies an emergency change on its own.
Description
A Password in Configuration File issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The pump stores some passwords in the configuration file, which are accessible if the pump is configured to allow external communications.
- CVSS 3.0
- 3.7 LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.97% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- smiths-medical/medfusion 4000 wireless syringe infusion pump
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/100665Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSMA-17-250-02AThird Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/100665Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSMA-17-250-02AThird Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.