CVE-2015-3459

The communication module on the Hospira LifeCare PCA Infusion System before 7.0 does not require authentication for root TELNET sessions, which allows remote attackers to modify the pump configuration via unspecified commands.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hospira:lifecare_pcainfusion_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:hospira:lifecare_pca3:-:*:*:*:*:*:*:*
cpe:2.3:h:hospira:lifecare_pca5:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2015-04-29 23:59

Updated : 2023-12-10 11:31


NVD link : CVE-2015-3459

Mitre link : CVE-2015-3459

CVE.ORG link : CVE-2015-3459


JSON object : View

Products Affected

hospira

  • lifecare_pca3
  • lifecare_pca5
  • lifecare_pcainfusion_firmware
CWE
CWE-264

Permissions, Privileges, and Access Controls