MEDIUM🇵🇱 Wersja polska

CVE-2014-5403

CVSS 6.8v2.0pub. 2015-04-03upd. 2026-05-06

Hospira MedNet before 6.1 uses hardcoded cryptographic keys for protection of data transmission from infusion pumps, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS Vector
AV:N/AC:L/Au:S/C:C/I:N/A:N
  • Hospira Mednet

    APP
    Hospira
    ≤ 5.8
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2014-5401CRITICAL9.8PL ✓same product

RCE w Hospira MedNet via podatne komponenty JBoss

CVE-2014-5405HIGH9.0same product

Hospira MedNet before 6.1 uses a hardcoded cleartext password to control SQL database authorization, which all...

CVE-2014-5400MEDIUM6.8same product

The installation component in Hospira MedNet before 6.1 places cleartext credentials in configuration files, w...

CVE-2015-7909HIGH7.3same vendor

Stack-based buffer overflow in Hospira Communication Engine (CE) before 1.2 in LifeCare PCA Infusion System 5....

CVE-2014-5406HIGH7.6same vendor

The Hospira LifeCare PCA Infusion System before 7.0 does not validate network traffic associated with sending ...