Lucene search

K

Symbiq Infusion System Firmware Security Vulnerabilities

cve
cve

CVE-2015-3952

Wireless keys are stored in plain text on Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends that customers close Port 20/FTP and Port 23/TELNET on the affected devices. Hosp...

7.5CVSS

7.3AI Score

0.002EPSS

2019-03-25 04:29 PM
26
cve
cve

CVE-2015-3953

Hard-coded accounts may be used to access Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends that customers close Port 20/FTP and Port 23/TELNET on the affected devices. Hosp...

9.8CVSS

9.2AI Score

0.002EPSS

2019-03-25 05:29 PM
23
cve
cve

CVE-2015-3954

Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior give unauthenticated users root privileges on Port 23/TELNET by default. An unauthorized user could issue commands to the pump. Hospira recomme...

9.8CVSS

9.5AI Score

0.002EPSS

2019-03-25 05:29 PM
28
cve
cve

CVE-2015-3956

Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior accept drug libraries, firmware updates, pump commands, and unauthorized configuration changes from unauthenticated devices on the host network...

9.8CVSS

9.3AI Score

0.002EPSS

2019-03-25 06:29 PM
29
cve
cve

CVE-2015-3965

Hospira Symbiq Infusion System 3.13 and earlier allows remote authenticated users to trigger "unanticipated operations" by leveraging "elevated privileges" for an unspecified call to an incorrectly exposed function.

8.8CVSS

8.3AI Score

0.002EPSS

2019-03-23 08:29 PM
28