peter bassill · operator
$ cve CVE-2017-12718 JSON

CVE-2017-12718 EXPLOIT

8.1
HIGH · CVSS 3.0 · EPSS 12.8% (pctl 96)

Patch early

A public exploit exists.

Description

A Classic Buffer Overflow issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. A third-party component used in the pump does not verify input buffer size prior to copying, leading to a buffer overflow, allowing remote code execution on the target device. The pump receives the potentially malicious input infrequently and under certain conditions, increasing the difficulty of exploitation.

Scoring

CVSS8.1 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS12.79% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-120
On CISA KEVno
Public exploityes
Published2018-02-15
Last modified2026-06-17

Affected (1)

VendorProduct
smiths-medicalmedfusion 4000 wireless syringe infusion pump

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD