CVE-2014-5406
Severity CVSS v4.0:
Pending analysis
Type:
CWE-345
Insufficient Verification of Data Authenticity
Publication date:
06/07/2015
Last modified:
12/04/2025
Description
The Hospira LifeCare PCA Infusion System before 7.0 does not validate network traffic associated with sending a (1) drug library, (2) software update, or (3) configuration change, which allows remote attackers to modify settings or medication data via packets on the (a) TELNET, (b) HTTP, (c) HTTPS, or (d) UPNP port. NOTE: this issue might overlap CVE-2015-3459.
Impact
Base Score 2.0
9.30
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:hospira:lifecare_pcainfusion_firmware:*:*:*:*:*:*:*:* | 5.0 (including) | |
cpe:2.3:h:hospira:lifecare_pca3:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:hospira:lifecare_pca5:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.fda.gov/MedicalDevices/Safety/AlertsandNotices/ucm446809.htm
- https://ics-cert.us-cert.gov/advisories/ICSA-15-125-01
- https://xs-sniper.com/blog/2015/06/08/hospira-plum-a-infusion-pump-vulnerabilities/
- http://www.fda.gov/MedicalDevices/Safety/AlertsandNotices/ucm446809.htm
- https://ics-cert.us-cert.gov/advisories/ICSA-15-125-01
- https://xs-sniper.com/blog/2015/06/08/hospira-plum-a-infusion-pump-vulnerabilities/