60
CVE-2017-12718
—CVSS 3.0
8.1 high
EPSS
13%p96
Published
()
Modified
Description
A Classic Buffer Overflow issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. A third-party component used in the pump does not verify input buffer size prior to copying, leading to a buffer overflow, allowing remote code execution on the target device. The pump receives the potentially malicious input infrequently and under certain conditions, increasing the difficulty of exploitation.
- Vendors
- smiths-medical
- Products
- medfusion 4000 wireless syringe infusion pump
- Weakness
- CWE-120, CWE-119
- Vector
- CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H