logo

FDA Safety Advisory Warns of Cyber Risk of Drug Pumps

ID: 535b94fc-9cf6-5986-ba38-7d2ae05c58be

STIX ID: report--535b94fc-9cf6-5986-ba38-7d2ae05c58be

Feed Name: Security Ledger

Threat Score
70/100

Date Published: 2015-05-14

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

The FDA issued a Safety Communication about critical software vulnerabilities in Hospira LifeCare PCA3/PCA5 infusion pumps that researchers found (unauthenticated Telnet/FTP access, root shell access, plaintext wireless keys, and insecure web interfaces). These flaws could allow remote or local attackers to alter dosage delivery, posing direct patient-safety risks; the advisory and ICS-CERT recommend isolating devices from untrusted networks, closing ports 20/23, performing integrity checks, and conducting clinical risk assessments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.