CVE-2016-8355

CRITICAL

Smiths-Medical CADD-Solis Medication Safety Software - Privilege Es...

Title source: llm

Description

An issue was discovered in Smiths-Medical CADD-Solis Medication Safety Software, Version 1.0; 2.0; 3.0; and 3.1. CADD-Solis Medication Safety Software grants an authenticated user elevated privileges on the SQL database, which would allow an authenticated user to modify drug libraries, add and delete users, and change user permissions. According to Smiths-Medical, physical access to the pump is required to install drug library updates.

Scores

CVSS v3 9.9
EPSS 0.0039
EPSS Percentile 59.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Classification

CWE
CWE-306
Status draft

Affected Products (4)

smiths-medical/cadd-solis_medication_safety_software
smiths-medical/cadd-solis_medication_safety_software
smiths-medical/cadd-solis_medication_safety_software
smiths-medical/cadd-solis_medication_safety_software

Timeline

Published Feb 13, 2017
Tracked Since Feb 18, 2026