Description
A Classic Buffer Overflow issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. A third-party component used in the pump does not verify input buffer size prior to copying, leading to a buffer overflow, allowing remote code execution on the target device. The pump receives the potentially malicious input infrequently and under certain conditions, increasing the difficulty of exploitation.
Published: 2018-02-15
Score: 8.1 High
EPSS: 25.8% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

No history.

Subscriptions

Smiths-medical Medfusion 4000 Wireless Syringe Infusion Pump
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-05T18:43:56.539Z

Reserved: 2017-08-09T00:00:00.000Z

Link: CVE-2017-12718

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-02-15T10:29:00.227

Modified: 2024-11-21T03:10:05.357

Link: CVE-2017-12718

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses