PatchSiren cyber security CVE debrief
CVE-2016-8358 Smiths Medical CVE debrief
CVE-2016-8358 describes a network-facing authentication weakness in Smiths-Medical CADD-Solis Medication Safety Software versions 1.0, 2.0, 3.0, and 3.1. According to NVD and the referenced ICS-CERT advisory, the software does not verify identities at communication endpoints, which can let a man-in-the-middle attacker intercept or access the communication channel between endpoints. NVD assigns CVSS 3.0 vector AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H, reflecting potentially high impact to confidentiality, integrity, and availability if the channel is successfully intercepted.
- Vendor
- Smiths Medical
- Product
- Cadd-Solis Medication Safety Software
- CVSS
- HIGH 8.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2016-08-05
- Original CVE updated
- 2025-06-05
- Advisory published
- 2016-08-05
- Advisory updated
- 2025-06-05
Who should care
Hospitals, clinical engineering teams, biomedical device administrators, and network/security teams that support Smiths-Medical CADD-Solis Medication Safety Software should treat this as relevant, especially if affected versions are in use on reachable networks.
Technical summary
The weakness is mapped to CWE-346 (Origin Validation Error). The affected versions are 1.0, 2.0, 3.0, and 3.1. The core issue is failure to verify endpoint identity during communication, which creates a man-in-the-middle opportunity. The official NVD entry lists the vulnerability as modified on 2026-05-13, but the CVE was published on 2017-02-13.
Defensive priority
High. The issue is network-reachable and can affect the security of communications for impacted software versions, with NVD scoring indicating high potential impact once exploitation conditions are met.
Recommended defensive actions
- Inventory whether Smiths-Medical CADD-Solis Medication Safety Software versions 1.0, 2.0, 3.0, or 3.1 are deployed.
- Review the ICS-CERT advisory and any vendor guidance for mitigation or compensating controls.
- Restrict network access to the software and related communication paths to trusted segments only.
- Monitor for anomalous or unexpected traffic that could indicate interception attempts on the communication channel.
- Plan upgrades or vendor-supported remediation where available, and document compensating controls if immediate replacement is not possible.
Evidence notes
All statements are based on the supplied NVD record and the referenced ICS-CERT/US-CERT advisory. The source corpus identifies the affected product, vulnerable versions, CWE-346, and the CVSS 3.0 vector. No exploit code or unverified remediation details are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-8358 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-8358
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-8358 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-8358
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://ics-cert.us-cert.gov/advisories/ICSMA-16-306-01
[email protected] - Third Party Advisory, US Government Resource
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.