Hospira LifeCare PCA Infusion System before 7.0 has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.
CVSS Vector
AV:N/AC:L/Au:N/C:P/I:N/A:NHospira Lifecare Pca3
HWHospiraall versionsHospira Lifecare Pca5
HWHospiraall versionsHospira Lifecare Pcainfusion Firmware
OSHospira≤ 5.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2014-5406HIGH7.6same product
The Hospira LifeCare PCA Infusion System before 7.0 does not validate network traffic associated with sending ...
CVE-2015-3955HIGH10.0same product
Stack-based buffer overflow in Hospira LifeCare PCA Infusion System 5.0 and earlier, and possibly other versio...
CVE-2015-3958HIGH7.8same product
Hospira LifeCare PCA Infusion System 5.0 and earlier, and possibly other versions, allows remote attackers to ...
CVE-2015-3459HIGH10.0same product
The communication module on the Hospira LifeCare PCA Infusion System before 7.0 does not require authenticatio...
CVE-2015-3957MEDIUM4.6same product
Hospira LifeCare PCA Infusion System before 7.0 stores private keys and certificates, which has unspecified im...