Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Hospira

First CVE: Apr 3, 2015Active for: 11 yearsTotal CVEs: 11
35.5
VTI Score
Medium

Hospira manufactures infusion pumps and medical-device control systems, including the LifeCare PCA line and networked medication-delivery platforms, which operate in clinical settings where availability and integrity are critical. The vendor's vulnerability profile centers on information-disclosure, memory-safety, and code-injection weaknesses, alongside configuration and authentication issues typical of embedded medical devices that were often designed before modern security practices became standard. Defenders managing these devices should prioritize network segmentation and access controls, and monitor Hospira's advisories closely; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Hospira over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 3, 2015
11 years ago
Most Recent CVE
Mar 26, 2019
2,677 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-5401CRITICAL
Hospira MedNet software version 5.8 and prior uses vulnerable versions of the JBoss Enterprise Application Platform software that may allow unauthenticated users to execute arbitra
Mar 26, 20199.833NONO
CVE-2014-5406HIGH
The Hospira LifeCare PCA Infusion System before 7.0 does not validate network traffic associated with sending a (1) drug library, (2) software update, or (3) configuration change,
Jul 6, 20159.328NONO
CVE-2015-3459HIGH
The communication module on the Hospira LifeCare PCA Infusion System before 7.0 does not require authentication for root TELNET sessions, which allows remote attackers to modify th
Apr 29, 201510.028NONO
CVE-2015-3955HIGH
Stack-based buffer overflow in Hospira LifeCare PCA Infusion System 5.0 and earlier, and possibly other versions, allows remote attackers to execute arbitrary code via unspecified
Jul 6, 201510.027NONO
CVE-2014-5405HIGH
Hospira MedNet before 6.1 uses a hardcoded cleartext password to control SQL database authorization, which allows remote authenticated users to bypass intended access restrictions
Apr 3, 20159.026NONO
CVE-2015-3958HIGH
Hospira LifeCare PCA Infusion System 5.0 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (forced manual reboot) via a flood of TCP pa
Jul 6, 20157.820NONO
CVE-2015-7909HIGH
Stack-based buffer overflow in Hospira Communication Engine (CE) before 1.2 in LifeCare PCA Infusion System 5.07, Plum A+ Infusion System 13.40, and Plum A+3 Infusion System 13.40
Jan 22, 20167.319NONO
CVE-2014-5403MEDIUM
Hospira MedNet before 6.1 uses hardcoded cryptographic keys for protection of data transmission from infusion pumps, which allows remote attackers to obtain sensitive information b
Apr 3, 20155.017NONO
CVE-2015-1011MEDIUM
Hospira LifeCare PCA Infusion System before 7.0 has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.
Jul 6, 20155.015NONO
CVE-2014-5400LOW
The installation component in Hospira MedNet before 6.1 places cleartext credentials in configuration files, which allows local users to obtain sensitive information by reading a f
Apr 3, 20152.115NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
9%
27%
55%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network2 (18.2%)
Unknown9 (81.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (18.2%)
High0 (0.0%)
Unknown9 (81.8%)
User Interaction
None2 (18.2%)
Unknown9 (81.8%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (18.2%)
Unknown9 (81.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Hospira.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Hospira — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Hospira's Products

View all 2 CNAs →

Top CWEs