CVE-2014-5406
Last modified
CVE-2014-5406 is a vulnerability of currently unknown severity. The Hospira LifeCare PCA Infusion System before 7.0 does not validate network traffic associated with sending a (1) drug library, (2) software update, or (3) configuration change, which allows remote attackers to modify settings or medication data via packets on the (a) TELNET, (b) HTTP, (c) HTTPS, or (d) UPNP port. NOTE: this issue might overlap CVE-2015-3459.. EPSS estimates a 1.24% chance of exploitation in the next 30 days.
Description
The Hospira LifeCare PCA Infusion System before 7.0 does not validate network traffic associated with sending a (1) drug library, (2) software update, or (3) configuration change, which allows remote attackers to modify settings or medication data via packets on the (a) TELNET, (b) HTTP, (c) HTTPS, or (d) UPNP port. NOTE: this issue might overlap CVE-2015-3459.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hospira | Lifecare Pcainfusion Firmware | <= 5.0 |
References
- http://www.fda.gov/MedicalDevices/Safety/AlertsandNotices/ucm446809.htmThird Party Advisory, US Government Resource
- http://www.fda.gov/MedicalDevices/Safety/AlertsandNotices/ucm446809.htmThird Party Advisory, US Government Resource
- https://ics-cert.us-cert.gov/advisories/ICSA-15-125-01Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-5406?
How severe is CVE-2014-5406?
How do I fix CVE-2014-5406?
Are you affected by CVE-2014-5406?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
