Vulnerability Details CVE-2017-12723
A Password in Configuration File issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The pump stores some passwords in the configuration file, which are accessible if the pump is configured to allow external communications.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 39.4%
CVSS Severity
CVSS v3 Score 3.7
CVSS v2 Score 4.3
Products affected by CVE-2017-12723
-
cpe:2.3:h:smiths-medical:medfusion_4000_wireless_syringe_infusion_pump:-
-
cpe:2.3:o:smiths-medical:medfusion_4000_wireless_syringe_infusion_pump:1.1
-
cpe:2.3:o:smiths-medical:medfusion_4000_wireless_syringe_infusion_pump:1.5
-
cpe:2.3:o:smiths-medical:medfusion_4000_wireless_syringe_infusion_pump:1.6