CVE Feed

    Dashboard / CVE / CVE-2015-1012

    CVE-2015-1012

    Wireless keys are stored in plain text on version 5 of the Hospira LifeCare PCA Infusion System. According to Hospira, version 3 of the LifeCare PCA Infusion System is not indicated for wireless use, is not shipped with wireless capabilities, and should not be modified to be used in a wireless capacity in a clinical setting. Hospira has developed a new version of the PCS Infusion System, version 7.0 that addresses the identified vulnerabilities. Version 7.0 has Port 20/FTP and Port 23/TELNET closed by default to prevent unauthorized access.

    Published:Mar 25, 2019
    Last Modified:Nov 21, 2024
    EPS:Mar 25, 2019
    EPSS Score:0.00112
    CVSS Score:7.5

    Affected Products

    Vendor
    Pfizer
    Product
    Lifecare Pca Infusion System
    Vendor
    Pfizer
    Product
    Lifecare Pca Infusion System Firmware

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High