CareFusion Pyxis SupplyStation 8.1 with hardware test tool before 1.0.16 has a hardcoded application password, which makes it easier for remote authenticated users to obtain application-file access via unspecified vectors.
References
Link Resource
https://ics-cert.us-cert.gov/advisories/ICSA-14-288-01 US Government Resource
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: icscert

Published: 2014-10-19T01:00:00

Updated: 2014-10-19T01:57:01

Reserved: 2014-08-22T00:00:00


Link: CVE-2014-5420

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2014-10-19T01:55:15.513

Modified: 2014-10-24T17:59:27.783


Link: CVE-2014-5420

JSON object: View

cve-icon Redhat Information

No data.

CWE