CVE-2015-3459
EUVD-2015-350229.04.2015, 23:59
The communication module on the Hospira LifeCare PCA Infusion System before 7.0 does not require authentication for root TELNET sessions, which allows remote attackers to modify the pump configuration via unspecified commands.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hospira | lifecare_pcainfusion_firmware | 𝑥 ≤ 5.0 |
| hospira | lifecare_pca3 | - |
| hospira | lifecare_pca5 | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References