The communication module on the Hospira LifeCare PCA Infusion System before 7.0 does not require authentication for root TELNET sessions, which allows remote attackers to modify the pump configuration via unspecified commands.
References
Link | Resource |
---|---|
http://hextechsecurity.com/?p=123 | Broken Link |
http://imgur.com/CEAnZjj | Not Applicable |
http://imgur.com/JHiWSqd | Not Applicable |
http://www.fda.gov/MedicalDevices/Safety/AlertsandNotices/ucm446809.htm | Third Party Advisory US Government Resource |
http://www.securityfocus.com/bid/74414 | Third Party Advisory VDB Entry |
https://ics-cert.us-cert.gov/advisories/ICSA-15-125-01 | Third Party Advisory US Government Resource |
https://twitter.com/dyngnosis/status/592671049487142913 | Press/Media Coverage |
https://twitter.com/dyngnosis/status/592743461977219072 | Press/Media Coverage |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2015-04-29T23:00:00
Updated: 2016-12-30T15:57:01
Reserved: 2015-04-29T00:00:00
Link: CVE-2015-3459
JSON object: View
NVD Information
Status : Analyzed
Published: 2015-04-29T23:59:00.057
Modified: 2017-01-03T19:16:30.773
Link: CVE-2015-3459
JSON object: View
Redhat Information
No data.
CWE