Pfizer's modest vulnerability footprint centers on infusion-pump systems and their embedded firmware, including the LifeCare PCA and Symbiq product lines, which operate in clinical settings where authentication and data confidentiality carry particular consequence. The recurring weakness classes—cleartext storage of sensitive information and exposure of sensitive data to unauthorized actors—reflect the security challenges of medical-device software where legacy protocols and limited processing power intersect with the need to protect patient and therapeutic data. Current exposure and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pfizer over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-3965HIGH Hospira Symbiq Infusion System 3.13 and earlier allows remote authenticated users to trigger "unanticipated operations" by leveraging "elevated privileges" for an unspecified call | Mar 23, 2019 | 8.8 | 23 | NO | NO |
CVE-2015-1012HIGH Wireless keys are stored in plain text on version 5 of the Hospira LifeCare PCA Infusion System. According to Hospira, version 3 of the LifeCare PCA Infusion System is not indicate | Mar 25, 2019 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pfizer.
Media articles that mention a CVE ID that affects a product developed by Pfizer — matched by CVE ID, not by vendor name.