5.9
CVSSv3

CVE-2017-12721

Published: 15/02/2018 Updated: 02/03/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

An Improper Certificate Validation issue exists in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The pump does not validate host certificates, leaving the pump vulnerable to a man-in-the-middle (MITM) attack.

Vulnerable Product Search on Vulmon Subscribe to Product

smiths-medical medfusion_4000_wireless_syringe_infusion_pump 1.1

smiths-medical medfusion_4000_wireless_syringe_infusion_pump 1.5

smiths-medical medfusion_4000_wireless_syringe_infusion_pump 1.6