ZeroHour

CVE-2017-12721

CVSS 3.0
5.9 medium
EPSS
<1%p50
Published
()
Modified
Description

An Improper Certificate Validation issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The pump does not validate host certificates, leaving the pump vulnerable to a man-in-the-middle (MITM) attack.

Vendors
smiths-medical
Products
medfusion 4000 wireless syringe infusion pump
Weakness
CWE-295
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news