10
CVSSv2

CVE-2015-3459

Published: 29/04/2015 Updated: 03/01/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The communication module on the Hospira LifeCare PCA Infusion System prior to 7.0 does not require authentication for root TELNET sessions, which allows remote malicious users to modify the pump configuration via unspecified commands.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hospira lifecare_pcainfusion_firmware

hospira lifecare_pca5 -

hospira lifecare_pca3 -