Lucene search

K
cveIcscertCVE-2014-5403
HistoryApr 03, 2015 - 10:59 a.m.

CVE-2014-5403

2015-04-0310:59:01
CWE-310
icscert
web.nvd.nist.gov
26
hospira mednet
cve-2014-5403
infusion pumps
data transmission
cryptographic keys
network security

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

50.9%

Hospira MedNet before 6.1 uses hardcoded cryptographic keys for protection of data transmission from infusion pumps, which allows remote attackers to obtain sensitive information by sniffing the network.

Affected configurations

Nvd
Node
hospiramednetRange5.8
VendorProductVersionCPE
hospiramednet*cpe:2.3:a:hospira:mednet:*:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

50.9%

Related for CVE-2014-5403