SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-12723

The pump stores some passwords in the configuration file, which are accessible if the pump is configured to allow external communications.

LOW 3.7EPSS 0.97%

Does this matter?

Lower severity and a low EPSS score (0.97%). Track it; it rarely justifies an emergency change on its own.

Description

A Password in Configuration File issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The pump stores some passwords in the configuration file, which are accessible if the pump is configured to allow external communications.

CVSS 3.0
3.7 LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
0.97% probability · 60th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
smiths-medical/medfusion 4000 wireless syringe infusion pump
Source
ics-cert@hq.dhs.gov

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.