Hospira manufactures infusion pumps and medical-device control systems, including the LifeCare PCA line and networked medication-delivery platforms, which operate in clinical settings where availability and integrity are critical. The vendor's vulnerability profile centers on information-disclosure, memory-safety, and code-injection weaknesses, alongside configuration and authentication issues typical of embedded medical devices that were often designed before modern security practices became standard. Defenders managing these devices should prioritize network segmentation and access controls, and monitor Hospira's advisories closely; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hospira over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-5401CRITICAL Hospira MedNet software version 5.8 and prior uses vulnerable versions of the JBoss Enterprise Application Platform software that may allow unauthenticated users to execute arbitra | Mar 26, 2019 | 9.8 | 33 | NO | NO |
CVE-2014-5406HIGH The Hospira LifeCare PCA Infusion System before 7.0 does not validate network traffic associated with sending a (1) drug library, (2) software update, or (3) configuration change, | Jul 6, 2015 | 9.3 | 28 | NO | NO |
CVE-2015-3459HIGH The communication module on the Hospira LifeCare PCA Infusion System before 7.0 does not require authentication for root TELNET sessions, which allows remote attackers to modify th | Apr 29, 2015 | 10.0 | 28 | NO | NO |
CVE-2015-3955HIGH Stack-based buffer overflow in Hospira LifeCare PCA Infusion System 5.0 and earlier, and possibly other versions, allows remote attackers to execute arbitrary code via unspecified | Jul 6, 2015 | 10.0 | 27 | NO | NO |
CVE-2014-5405HIGH Hospira MedNet before 6.1 uses a hardcoded cleartext password to control SQL database authorization, which allows remote authenticated users to bypass intended access restrictions | Apr 3, 2015 | 9.0 | 26 | NO | NO |
CVE-2015-3958HIGH Hospira LifeCare PCA Infusion System 5.0 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (forced manual reboot) via a flood of TCP pa | Jul 6, 2015 | 7.8 | 20 | NO | NO |
CVE-2015-7909HIGH Stack-based buffer overflow in Hospira Communication Engine (CE) before 1.2 in LifeCare PCA Infusion System 5.07, Plum A+ Infusion System 13.40, and Plum A+3 Infusion System 13.40 | Jan 22, 2016 | 7.3 | 19 | NO | NO |
CVE-2014-5403MEDIUM Hospira MedNet before 6.1 uses hardcoded cryptographic keys for protection of data transmission from infusion pumps, which allows remote attackers to obtain sensitive information b | Apr 3, 2015 | 5.0 | 17 | NO | NO |
CVE-2015-1011MEDIUM Hospira LifeCare PCA Infusion System before 7.0 has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. | Jul 6, 2015 | 5.0 | 15 | NO | NO |
The installation component in Hospira MedNet before 6.1 places cleartext credentials in configuration files, which allows local users to obtain sensitive information by reading a f | Apr 3, 2015 | 2.1 | 15 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hospira.
Media articles that mention a CVE ID that affects a product developed by Hospira — matched by CVE ID, not by vendor name.