Hospira LifeCare PCA Infusion System
Summary
| CVE | CVE-2014-5406 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-07-06 19:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The Hospira LifeCare PCA Infusion System before 7.0 does not validate network traffic associated with sending a (1) drug library, (2) software update, or (3) configuration change, which allows remote attackers to modify settings or medication data via packets on the (a) TELNET, (b) HTTP, (c) HTTPS, or (d) UPNP port. NOTE: this issue might overlap CVE-2015-3459. |
Risk And Classification
Primary CVSS: v2.0 9.3 from [email protected]
AV:N/AC:M/Au:N/C:C/I:C/A:C
Problem Types: CWE-345 | CWE-345 CWE-345
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 2.0 | [email protected] | Primary | 9.3 | AV:N/AC:M/Au:N/C:C/I:C/A:C | |
| 2.0 | [email protected] | Secondary | 7.6 | AV:N/AC:H/Au:N/C:C/I:C/A:C | |
| 2.0 | CNA | CVSS | 7.6 | AV:N/AC:H/Au:N/C:C/I:C/A:C |
CVSS v2.0 Breakdown
AV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Hospira | Lifecare Pca3 | - | All | All | All |
| Hardware | Hospira | Lifecare Pca5 | - | All | All | All |
| Operating System | Hospira | Lifecare Pcainfusion Firmware | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Hospira | LifeCare PCA Infusion System | affected 5.0 custom | Not specified |
| CNA | Hospira | LifeCare PCA Infusion System | unaffected 7.0 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Vulnerabilities of Hospira LifeCare PCA3 and PCA5 Infusion Pump Systems: FDA Safety Communication | af854a3a-2127-422b-91ae-364da2661108 | www.fda.gov | Third Party Advisory, US Government Resource |
| github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2015/icsa-15-12... | [email protected] | github.com | |
| Hospira LifeCare PCA Infusion System Vulnerabilities (Update B) | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| www.cisa.gov/news-events/ics-advisories/icsa-15-125-01 | [email protected] | www.cisa.gov | |
| Billy (BK) Rios » Hospira Plum A+ Infusion Pump Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | xs-sniper.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Billy Rios (en)
Additional Advisory Data
Solutions
CNA: ICS-CERT has been working with Hospira since May 2014 to address the vulnerabilities in the LifeCare PCA Infusion System. Hospira has developed a new version of the PCS Infusion System, Version 7.0 that addresses the identified vulnerabilities. According to Hospira, Version 7.0 has Port 20/FTP and Port 23/TELNET closed by default to prevent unauthorized access. Existing PCA Infusion Systems running Version 5.0 can be upgraded to Version 7.0 when it becomes available. Hospira’s Version 7.0 is being reviewed by the FDA prior to its release. The release date for Version 7.0 of the LifeCare PCA Infusion System has not been determined. For additional information about Hospira’s new release, contact Hospira’s technical support at 1‑800-241-4002.