CVE Tools

Hospira

10 CVEs tracked since 2015. Since Apr 2015, none of them reached CISA KEV.

Hospira CVEs per month

Apr 2015 to Jan 2016. Point at a month, or focus the strip and use the arrow keys.
Hospira CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2015-0440
2015-05null or fewer
2015-06null or fewer
2015-0750
2015-08null or fewer
2015-09null or fewer
2015-10null or fewer
2015-11null or fewer
2015-12null or fewer
2016-0110

Products

The products that kept showing up in Hospira's monthly top three, with their CVEs summed over those months.

  1. Lifecare Pcainfusion Firmware62 months
  2. Mednet31 month
  3. Lifecare Pca Infusion System22 months
  4. Lifecare PCA322 months
  5. Communication Engine11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Hospira.

  1. CVE-2014-5401Hospira MedNet Code Injection9.8
  2. CVE-2015-1012Wireless keys are stored in plain text on version 5 of the Hospira LifeCare PCA Infusion System. According to Hospira, version 3 of the LifeCare PCA Infusion System is not indicated for wireless us...7.5
  3. CVE-2015-3956Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior accept drug libraries, firmware updates, ...9.8
  4. CVE-2015-3954Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior give unauthenticated users root privilege...9.8
  5. CVE-2015-3953Hard-coded accounts may be used to access Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior...9.8
  6. CVE-2015-3952Wireless keys are stored in plain text on Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior...7.5
  7. CVE-2015-3965Hospira Symbiq Infusion System 3.13 and earlier allows remote authenticated users to trigger "unanticipated operations" by leveraging "elevated privileges" for an unspecified call to an incorrectly...8.8
  8. CVE-2015-7909Stack-based buffer overflow in Hospira Communication Engine (CE) before 1.2 in LifeCare PCA Infusion System 5.07, Plum A+ Infusion System 13.40, and Plum A+3 Infusion System 13.40 allows remote att...7.3
  9. CVE-2015-3957Hospira LifeCare PCA Infusion System before 7.0 stores private keys and certificates, which has unspecified impact and attack vectors.4.6
  10. CVE-2015-3958Hospira LifeCare PCA Infusion System 5.0 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (forced manual reboot) via a flood of TCP packets.7.8
  11. CVE-2015-3955Stack-based buffer overflow in Hospira LifeCare PCA Infusion System 5.0 and earlier, and possibly other versions, allows remote attackers to execute arbitrary code via unspecified vectors.10.0
  12. CVE-2015-1011Hospira LifeCare PCA Infusion System before 7.0 has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.5.0
  13. CVE-2014-5406Hospira LifeCare PCA Infusion System7.6
  14. CVE-2015-3459The communication module on the Hospira LifeCare PCA Infusion System before 7.0 does not require authentication for root TELNET sessions, which allows remote attackers to modify the pump configurat...10.0
  15. CVE-2014-5403Hospira MedNet Use of Hard-coded Cryptographic Key6.8

The record

Peak rank
#21 in Jul 2015
Busiest month shown
Jul 2015, 5 CVEs
Months with a KEV entry
0 since Apr 2015
Monthly snapshots
3 since 2015
Hospira's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store