CVE-2017-12718 EXPLOIT
8.1
HIGH · CVSS 3.0 · EPSS 12.8% (pctl 96)
Patch early
A public exploit exists.
Description
A Classic Buffer Overflow issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. A third-party component used in the pump does not verify input buffer size prior to copying, leading to a buffer overflow, allowing remote code execution on the target device. The pump receives the potentially malicious input infrequently and under certain conditions, increasing the difficulty of exploitation.
Scoring
| CVSS | 8.1 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 12.79% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-120 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-02-15 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| smiths-medical | medfusion 4000 wireless syringe infusion pump |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Smiths Medical Medfusion 4000 - 'DHCP' Denial of Service | 2018-01-18 |
References
- http://www.securityfocus.com/bid/100665
- http://www.securityfocus.com/bid/101252
- https://ics-cert.us-cert.gov/advisories/ICSMA-17-250-02A
- https://www.exploit-db.com/exploits/43776/
- http://www.securityfocus.com/bid/100665
- http://www.securityfocus.com/bid/101252
- https://ics-cert.us-cert.gov/advisories/ICSMA-17-250-02A
- https://www.exploit-db.com/exploits/43776/
→ the Explorer · watch your stack · NVD