CVE-2017-11580 describes a memory corruption vulnerability in Blipcare Wifi blood pressure monitor BP700 10.1 devices. This flaw allows an attacker to cause a Denial of Service by sending a large string within HTTP headers when connected to the device's open wireless network. The vulnerability stems from insufficient memory allocation (256KB) and improper string handling, leading to device unresponsiveness. The vulnerability has a CVSS score of 6.5 (Medium), indicating an adjacent network attack vector with low complexity and high impact on availability. No user interaction is required, and the scope is unchanged. There is no known active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the CISA KEV catalog. However, the CVE has garnered some community discussion, with two mentions, including one referencing exploitation by state-sponsored actors, despite the Hot List status being "Inactive."
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= bp700_10.1CPE matchmatch criteria | cpe:2.3:o:blipcare:wi-fi_blood_pressure_monitor_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.