9.3
CVSSv2

CVE-2014-5406

Published: 06/07/2015 Updated: 08/07/2015
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The Hospira LifeCare PCA Infusion System prior to 7.0 does not validate network traffic associated with sending a (1) drug library, (2) software update, or (3) configuration change, which allows remote malicious users to modify settings or medication data via packets on the (a) TELNET, (b) HTTP, (c) HTTPS, or (d) UPNP port. NOTE: this issue might overlap CVE-2015-3459.

Vulnerable Product Search on Vulmon Subscribe to Product

hospira lifecare_pcainfusion_firmware