CVE-2015-3958
Severity CVSS v4.0:
Pending analysis
Type:
CWE-19
Data Handling
Publication date:
06/07/2015
Last modified:
12/04/2025
Description
Hospira LifeCare PCA Infusion System 5.0 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (forced manual reboot) via a flood of TCP packets.
Impact
Base Score 2.0
7.80
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:hospira:lifecare_pcainfusion_firmware:*:*:*:*:*:*:*:* | 5.0 (including) | |
| cpe:2.3:h:hospira:lifecare_pca3:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hospira:lifecare_pca5:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.fda.gov/MedicalDevices/Safety/AlertsandNotices/ucm446809.htm
- http://www.securityfocus.com/bid/75138
- https://ics-cert.us-cert.gov/advisories/ICSA-15-125-01B
- http://www.fda.gov/MedicalDevices/Safety/AlertsandNotices/ucm446809.htm
- http://www.securityfocus.com/bid/75138
- https://ics-cert.us-cert.gov/advisories/ICSA-15-125-01B



