Hospira MedNet before 6.1 uses hardcoded cryptographic keys for protection of data transmission from infusion pumps, which allows remote attackers to obtain sensitive information by sniffing the network.
CVSS Vector
AV:N/AC:L/Au:S/C:C/I:N/A:NHospira Mednet
APPHospira≤ 5.8
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2014-5401CRITICAL9.8PL ✓same product
RCE w Hospira MedNet via podatne komponenty JBoss
CVE-2014-5405HIGH9.0same product
Hospira MedNet before 6.1 uses a hardcoded cleartext password to control SQL database authorization, which all...
CVE-2014-5400MEDIUM6.8same product
The installation component in Hospira MedNet before 6.1 places cleartext credentials in configuration files, w...
CVE-2015-7909HIGH7.3same vendor
Stack-based buffer overflow in Hospira Communication Engine (CE) before 1.2 in LifeCare PCA Infusion System 5....
CVE-2014-5406HIGH7.6same vendor
The Hospira LifeCare PCA Infusion System before 7.0 does not validate network traffic associated with sending ...