Pyxis SupplyStation System CVE-2014-5421 Hardcoded Credentials Security Bypass Vulnerability
BID:70599
Info
Pyxis SupplyStation System CVE-2014-5421 Hardcoded Credentials Security Bypass Vulnerability
| Bugtraq ID: | 70599 |
| Class: | Design Error |
| CVE: |
CVE-2014-5421 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 15 2014 12:00AM |
| Updated: | Oct 15 2014 12:00AM |
| Credit: | Billy Rios |
| Vulnerable: |
CareFusion Pyxis SupplyStation System 8.1 |
| Not Vulnerable: | |
Discussion
Pyxis SupplyStation System CVE-2014-5421 Hardcoded Credentials Security Bypass Vulnerability
CareFusion Pyxis SupplyStation System is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass the authentication mechanism and gain access to the vulnerable device.
Pyxis SupplyStation system 8.1 and prior are vulnerable.
CareFusion Pyxis SupplyStation System is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass the authentication mechanism and gain access to the vulnerable device.
Pyxis SupplyStation system 8.1 and prior are vulnerable.
Exploit / POC
Pyxis SupplyStation System CVE-2014-5421 Hardcoded Credentials Security Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Pyxis SupplyStation System CVE-2014-5421 Hardcoded Credentials Security Bypass Vulnerability
References:
References:
- Pyxis SupplyStation System Homepage (carefusion)
- CareFusion Pyxis SupplyStation System Vulnerabilities (ICS-CERT)