Multiple vulnerabilities in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump



Published: 2017-09-11
Risk High
Patch available NO
Number of vulnerabilities 8
CVE-ID CVE-2017-12718
CVE-2017-12722
CVE-2017-12725
CVE-2017-12720
CVE-2017-12724
CVE-2017-12726
CVE-2017-12721
CVE-2017-12723
CWE-ID CWE-120
CWE-125
CWE-798
CWE-284
CWE-295
CWE-260
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
Medfusion 4000 Wireless Syringe Infusion Pump
Hardware solutions / Firmware

Vendor Smiths Medical

Security Bulletin

This security bulletin contains information about 8 vulnerabilities.

1) Buffer overflow

EUVDB-ID: #VU8225

Risk: High

CVSSv3.1: 9.1 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:U/RC:C]

CVE-ID: CVE-2017-12718

CWE-ID: CWE-120 - Buffer overflow

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists due to boundary error when handling malicious input. A remote attacker can send specially crafted data, trigger memory corruption and execute arbitrary code.

Successful exploitation of the vulnerability may result in system compromise.

Mitigation

Smiths Medical is planning to release Version 1.6.1 for the Medfusion 4000 Wireless Syringe Infusion Pump in January, 2018.

Vulnerable software versions

Medfusion 4000 Wireless Syringe Infusion Pump: 1.1 - 1.6

External links

http://ics-cert.us-cert.gov/advisories/ICSMA-17-250-02


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Out-of-bounds read

EUVDB-ID: #VU8226

Risk: Low

CVSSv3.1: 4.9 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:U/RC:C]

CVE-ID: CVE-2017-12722

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to out-of-bounds read. A remote attacker can trigger the communications module to crash.

Successful exploitation of the vulnerability results in denial of service.

Mitigation

Smiths Medical is planning to release Version 1.6.1 for the Medfusion 4000 Wireless Syringe Infusion Pump in January, 2018.

Vulnerable software versions

Medfusion 4000 Wireless Syringe Infusion Pump: 1.1 - 1.6

External links

http://ics-cert.us-cert.gov/advisories/ICSMA-17-250-02


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Use of hardcoded credentials

EUVDB-ID: #VU8227

Risk: Low

CVSSv3.1: 6.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:U/RC:C]

CVE-ID: CVE-2017-12725

CWE-ID: CWE-798 - Use of Hard-coded Credentials

Exploit availability: No

Description

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The weakness exists due to use of hard-coded credentials to automatically establish a wireless network connection by the pump with default network configuration. A remote attacker can trigger improper attachment of the network stack to the wireless network by the pump and direct all network traffic over the wired Ethernet connection.

Mitigation

Smiths Medical is planning to release Version 1.6.1 for the Medfusion 4000 Wireless Syringe Infusion Pump in January, 2018.

Vulnerable software versions

Medfusion 4000 Wireless Syringe Infusion Pump: 1.1 - 1.6

External links

http://ics-cert.us-cert.gov/advisories/ICSMA-17-250-02


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

4) Improper access control

EUVDB-ID: #VU8228

Risk: Low

CVSSv3.1: 7.4 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:C]

CVE-ID: CVE-2017-12720

CWE-ID: CWE-284 - Improper Access Control

Exploit availability: No

Description

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The weakness exists due to improper access control. A remote attacker can bypass authentication and gain access to the FTP server. Successful exploitation of the vulnerability is possible if the pump is configured to allow FTP connections.

Mitigation

Smiths Medical is planning to release Version 1.6.1 for the Medfusion 4000 Wireless Syringe Infusion Pump in January, 2018.

Vulnerable software versions

Medfusion 4000 Wireless Syringe Infusion Pump: 1.1 - 1.6

External links

http://ics-cert.us-cert.gov/advisories/ICSMA-17-250-02


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

5) Use of hardcoded credentials

EUVDB-ID: #VU8229

Risk: Low

CVSSv3.1: 7.4 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:C]

CVE-ID: CVE-2017-12724

CWE-ID: CWE-798 - Use of Hard-coded Credentials

Exploit availability: No

Description

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The weakness exists due to FTP server on the pump contains not fully initialized hardcoded credentials. A remote attacker can bypass authentication and gain access to the FTP server. Successful exploitation of the vulnerability is possible if the pump is configured to allow FTP connections.

Mitigation

Smiths Medical is planning to release Version 1.6.1 for the Medfusion 4000 Wireless Syringe Infusion Pump in January, 2018.

Vulnerable software versions

Medfusion 4000 Wireless Syringe Infusion Pump: 1.1 - 1.6

External links

http://ics-cert.us-cert.gov/advisories/ICSMA-17-250-02


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

6) Use of hardcoded credentials

EUVDB-ID: #VU8230

Risk: Low

CVSSv3.1: 5.1 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:U/RC:C]

CVE-ID: CVE-2017-12726

CWE-ID: CWE-798 - Use of Hard-coded Credentials

Exploit availability: No

Description

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The weakness exists due to use of hardcoded credentials by Telnet on the pump. A remote attacker can bypass security restrictions. Successful exploitation of the vulnerability is possible if the pump is configured to allow external communications.

Mitigation

Smiths Medical is planning to release Version 1.6.1 for the Medfusion 4000 Wireless Syringe Infusion Pump in January, 2018.

Vulnerable software versions

Medfusion 4000 Wireless Syringe Infusion Pump: 1.1 - 1.6

External links

http://ics-cert.us-cert.gov/advisories/ICSMA-17-250-02


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

7) Man-in-the-middle attack

EUVDB-ID: #VU8231

Risk: Low

CVSSv3.1: 6.9 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:U/RC:C]

CVE-ID: CVE-2017-12721

CWE-ID: CWE-295 - Improper Certificate Validation

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform man-in-the-middle attack.

The weakness exists due to insufficient verification of host certificate. A remote attacker can conduct a man-in-the-middle attack to access and modify data.

Mitigation

Smiths Medical is planning to release Version 1.6.1 for the Medfusion 4000 Wireless Syringe Infusion Pump in January, 2018.

Vulnerable software versions

Medfusion 4000 Wireless Syringe Infusion Pump: 1.1 - 1.6

External links

http://ics-cert.us-cert.gov/advisories/ICSMA-17-250-02


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

8) Information disclosure

EUVDB-ID: #VU8232

Risk: Low

CVSSv3.1: 3.4 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:U/RC:C]

CVE-ID: CVE-2017-12723

CWE-ID: CWE-260 - Password in Configuration File

Exploit availability: No

Description

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The weakness exists due to the pump stores some passwords in the configuration file. A remote attacker can gain access to arbitrary data. Successful exploitation of the vulnerability is possible if the pump is configured to allow external communications.

Mitigation

Smiths Medical is planning to release Version 1.6.1 for the Medfusion 4000 Wireless Syringe Infusion Pump in January, 2018.

Vulnerable software versions

Medfusion 4000 Wireless Syringe Infusion Pump: 1.1 - 1.6

External links

http://ics-cert.us-cert.gov/advisories/ICSMA-17-250-02


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###