VulnerabilityModified
CVE-2015-3459
The communication module on the Hospira LifeCare PCA Infusion System before 7.0 does not require authentication for root TELNET sessions, which allows remote attackers to modify the pump configuration via unspecified commands.
HIGH 10.0EPSS 5.06%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.06%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The communication module on the Hospira LifeCare PCA Infusion System before 7.0 does not require authentication for root TELNET sessions, which allows remote attackers to modify the pump configuration via unspecified commands.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 5.06% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- hospira/lifecare pcainfusion firmware · hospira/lifecare pca3 · hospira/lifecare pca5
- Source
- cve@mitre.org
References
- http://hextechsecurity.com/?p=123Broken Link
- http://imgur.com/CEAnZjjNot Applicable
- http://imgur.com/JHiWSqdNot Applicable
- http://www.fda.gov/MedicalDevices/Safety/AlertsandNotices/ucm446809.htmThird Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/74414Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-15-125-01Third Party Advisory, US Government Resource
- https://twitter.com/dyngnosis/status/592671049487142913Press/Media Coverage
- https://twitter.com/dyngnosis/status/592743461977219072Press/Media Coverage
- http://hextechsecurity.com/?p=123Broken Link
- http://imgur.com/CEAnZjjNot Applicable
- http://imgur.com/JHiWSqdNot Applicable
- http://www.fda.gov/MedicalDevices/Safety/AlertsandNotices/ucm446809.htmThird Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/74414Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-15-125-01Third Party Advisory, US Government Resource
- https://twitter.com/dyngnosis/status/592671049487142913Press/Media Coverage
- https://twitter.com/dyngnosis/status/592743461977219072Press/Media Coverage
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.