Hospira MedNet before 6.1 uses a hardcoded cleartext password to control SQL database authorization, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password.
CVSS Vector
AV:N/AC:L/Au:S/C:C/I:C/A:CHospira Mednet
APPHospira≤ 5.8
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2014-5401CRITICAL9.8PL ✓same product
RCE w Hospira MedNet via podatne komponenty JBoss
CVE-2014-5400MEDIUM6.8same product
The installation component in Hospira MedNet before 6.1 places cleartext credentials in configuration files, w...
CVE-2014-5403MEDIUM6.8same product
Hospira MedNet before 6.1 uses hardcoded cryptographic keys for protection of data transmission from infusion ...
CVE-2015-7909HIGH7.3same vendor
Stack-based buffer overflow in Hospira Communication Engine (CE) before 1.2 in LifeCare PCA Infusion System 5....
CVE-2014-5406HIGH7.6same vendor
The Hospira LifeCare PCA Infusion System before 7.0 does not validate network traffic associated with sending ...