CVE-2015-3459
Summary
| CVE | CVE-2015-3459 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-04-29 23:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The communication module on the Hospira LifeCare PCA Infusion System before 7.0 does not require authentication for root TELNET sessions, which allows remote attackers to modify the pump configuration via unspecified commands. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Hospira | Lifecare Pca3 | - | All | All | All |
| Hardware | Hospira | Lifecare Pca5 | - | All | All | All |
| Operating System | Hospira | Lifecare Pcainfusion Firmware | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Hospira Lifecare PCA Infusion Pump CVE-2015-3459 Authentication Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Vulnerabilities of Hospira LifeCare PCA3 and PCA5 Infusion Pump Systems: FDA Safety Communication | af854a3a-2127-422b-91ae-364da2661108 | www.fda.gov | Third Party Advisory, US Government Resource |
| Imgur: The most awesome images on the Internet | af854a3a-2127-422b-91ae-364da2661108 | imgur.com | Not Applicable |
| dyngnosis on Twitter: "Don't buy a Hospira PCA drug pump to do security stuff. Busybx no passwd shell on 23, no-auth CGIs, also never hook it up to a human being" | af854a3a-2127-422b-91ae-364da2661108 | twitter.com | Press/Media Coverage |
| Imgur: The most awesome images on the Internet | af854a3a-2127-422b-91ae-364da2661108 | imgur.com | Not Applicable |
| dyngnosis on Twitter: "@SushiDude @XSSniper @scotterven @WIRED Hospira "Lifecare PCA Drug Infusion Pump" http://t.co/JjAVF3J9KO SW ver 412 http://t.co/rSS0gqtfby" | af854a3a-2127-422b-91ae-364da2661108 | twitter.com | Press/Media Coverage |
| Hospira LifeCare PCA Infusion System Vulnerabilities (Update B) | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| Hospira PCA3 Drug Infusion Pump | 0xTech Security | af854a3a-2127-422b-91ae-364da2661108 | hextechsecurity.com | Broken Link |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.