← All CVEs

CVE-2017-12718

high · 8.1

A Classic Buffer Overflow issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. A third-party component used in the pump does not verify input buffer size prior to copying, leading to a buffer overflow, allowing remote code execution on the target device. The pump receives the potentially malicious input infrequently and under certain conditions, increasing the difficulty of exploitation.

8.1
CVSS
12.8%
EPSS (exploit prob.)
96th
EPSS percentile
2018-02-15
Published

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-120CWE-119

Affected products

VendorProductAffected versions
smiths-medicalmedfusion_4000_wireless_syringe_infusion_pump1.1
smiths-medicalmedfusion_4000_wireless_syringe_infusion_pump1.5
smiths-medicalmedfusion_4000_wireless_syringe_infusion_pump1.6
smiths-medicalmedfusion_4000_wireless_syringe_infusion_pumpall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-12718