CVE-2014-5406 describes a critical vulnerability in Hospira LifeCare PCA Infusion Systems prior to version 7.0, specifically affecting the PCA3, PCA5, and PCA Infusion firmware. The flaw stems from a lack of network traffic validation when sending drug library, software update, or configuration changes, allowing remote attackers to alter device settings or medication data. With a CVSS score of 9.3, this vulnerability is highly severe due to its network-based attack vector, medium complexity, and complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.0CPE matchmatch criteria | cpe:2.3:o:hospira:lifecare_pcainfusion_firmware:*:*:*:*:*:*:*:* | ||
>= 0, <= 5.0CPE match | cpe:2.3:h:hospira:lifecare_pca_infusion_system:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.