CVE-2017-12723: Smiths-Medical Medfusion 4000 Wireless Syringe Infusion Pump

Low severity, CVSS 3.7. EPSS: 1% chance of exploitation in the next 30 days.

A Password in Configuration File issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The pump stores some passwords in the configuration file, which are accessible if the pump is configured to allow external communications.

Affected products

  • Smiths-Medical Medfusion 4000 Wireless Syringe Infusion Pump: version 1.1 only; version 1.5 only; version 1.6 only

Published 2018-02-15. Last modified 2026-06-17.