#VU8227 Use of hardcoded credentials in Medfusion 4000 Wireless Syringe Infusion Pump - CVE-2017-12725

 

#VU8227 Use of hardcoded credentials in Medfusion 4000 Wireless Syringe Infusion Pump - CVE-2017-12725

Published: September 11, 2017 / Updated: September 11, 2017


Vulnerability identifier: #VU8227
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2017-12725
CWE-ID: CWE-798
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Medfusion 4000 Wireless Syringe Infusion Pump
Software vendor:
Smiths Medical

Description

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The weakness exists due to use of hard-coded credentials to automatically establish a wireless network connection by the pump with default network configuration. A remote attacker can trigger improper attachment of the network stack to the wireless network by the pump and direct all network traffic over the wired Ethernet connection.

Remediation

Smiths Medical is planning to release Version 1.6.1 for the Medfusion 4000 Wireless Syringe Infusion Pump in January, 2018.

External links