Smiths Medical's vulnerability footprint centers on medical infusion and medication-delivery devices such as wireless syringe pumps and associated safety software, which operate in clinical environments where availability and patient safety are critical. The vendor's disclosed vulnerabilities reflect the connectivity and control-system aspects of these products rather than a broad application portfolio. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Smiths Medical over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-12718HIGH A Classic Buffer Overflow issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. A third-party component used in the pump | Feb 15, 2018 | 8.1 | 43 | NO | YES |
CVE-2016-8355CRITICAL An issue was discovered in Smiths-Medical CADD-Solis Medication Safety Software, Version 1.0; 2.0; 3.0; and 3.1. CADD-Solis Medication Safety Software grants an authenticated user | Feb 13, 2017 | 9.9 | 31 | NO | NO |
CVE-2016-8358HIGH An issue was discovered in Smiths-Medical CADD-Solis Medication Safety Software, Version 1.0; 2.0; 3.0; and 3.1. The affected software does not verify the identities at communicati | Feb 13, 2017 | 8.5 | 26 | NO | NO |
CVE-2017-12724HIGH A Use of Hard-coded Credentials issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The FTP server on the pump contains | Feb 15, 2018 | 8.1 | 23 | NO | NO |
CVE-2017-12726HIGH A Use of Hard-coded Password issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. Telnet on the pump uses hardcoded cred | Feb 15, 2018 | 7.3 | 22 | NO | NO |
CVE-2017-12721MEDIUM An Improper Certificate Validation issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The pump does not validate host | Feb 15, 2018 | 5.9 | 21 | NO | NO |
CVE-2017-12720HIGH An Improper Access Control issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The FTP server on the pump does not requ | Feb 15, 2018 | 8.1 | 21 | NO | NO |
CVE-2017-12725MEDIUM A Use of Hard-coded Credentials issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The pump with default network confi | Feb 15, 2018 | 5.6 | 16 | NO | NO |
CVE-2017-12722MEDIUM An Out-of-bounds Read issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. A third-party component used in the pump read | Feb 15, 2018 | 5.3 | 16 | NO | NO |
A Password in Configuration File issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The pump stores some passwords in | Feb 15, 2018 | 3.7 | 15 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Smiths Medical.
Media articles that mention a CVE ID that affects a product developed by Smiths Medical — matched by CVE ID, not by vendor name.