CVE-2017-12723: Smiths-Medical Medfusion 4000 Wireless Syringe Infusion Pump
Low severity, CVSS 3.7. EPSS: 1% chance of exploitation in the next 30 days.
A Password in Configuration File issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The pump stores some passwords in the configuration file, which are accessible if the pump is configured to allow external communications.
Affected products
- Smiths-Medical Medfusion 4000 Wireless Syringe Infusion Pump: version 1.1 only; version 1.5 only; version 1.6 only
Published 2018-02-15. Last modified 2026-06-17.