CVE-2017-12721
MEDIUMSmiths Medical Medfusion 4000 Wireless Syringe Infusion Pump 1.1, 1.5, 1.6 - Improper Certificate Validation
Title source: llmDescription
An Improper Certificate Validation issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The pump does not validate host certificates, leaving the pump vulnerable to a man-in-the-middle (MITM) attack.
References (2)
Core 2
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSMA-17-250-02A
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/100665
Scores
CVSS v3
5.9
EPSS
0.0070
EPSS Percentile
48.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-295
Status
published
Products (3)
smiths-medical/medfusion_4000_wireless_syringe_infusion_pump
1.1
smiths-medical/medfusion_4000_wireless_syringe_infusion_pump
1.5
smiths-medical/medfusion_4000_wireless_syringe_infusion_pump
1.6
Published
Feb 15, 2018
Tracked Since
Feb 18, 2026