Pifzer's vulnerability footprint is concentrated in medical infusion-delivery systems, including the Plum A+ and SymbiQ product lines, where recurring exposure centers on sensitive-data handling and authorization controls. The durable weakness signal reflects challenges endemic to connected medical devices: cleartext storage of sensitive information, exposure of credentials and authentication data to unauthorized actors, improper authorization logic, and insufficient verification of data authenticity—issues that carry particular weight in clinical environments where device integrity directly affects patient safety. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pifzer over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-3954CRITICAL Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior give unauthenticated use | Mar 25, 2019 | 9.8 | 30 | NO | NO |
CVE-2015-3956CRITICAL Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior accept drug libraries, f | Mar 25, 2019 | 9.8 | 29 | NO | NO |
CVE-2015-3953CRITICAL Hard-coded accounts may be used to access Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, versi | Mar 25, 2019 | 9.8 | 24 | NO | NO |
CVE-2015-3952HIGH Wireless keys are stored in plain text on Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, versi | Mar 25, 2019 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pifzer.
Media articles that mention a CVE ID that affects a product developed by Pifzer — matched by CVE ID, not by vendor name.