3.7
CVSSv3

CVE-2017-12723

Published: 15/02/2018 Updated: 02/03/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 3.7 | Impact Score: 1.4 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

A Password in Configuration File issue exists in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The pump stores some passwords in the configuration file, which are accessible if the pump is configured to allow external communications.

Vulnerable Product Search on Vulmon Subscribe to Product

smiths-medical medfusion_4000_wireless_syringe_infusion_pump 1.1

smiths-medical medfusion_4000_wireless_syringe_infusion_pump 1.6

smiths-medical medfusion_4000_wireless_syringe_infusion_pump 1.5