Drug Pumps Vulnerable to trivial Hacks, DHS warns
ID: b5ab1e4d-e7fd-55d1-896f-2e9e95fb68d9
STIX ID: report--b5ab1e4d-e7fd-55d1-896f-2e9e95fb68d9
Feed Name: Security Ledger
Threat Score
Hospira's MedNet infusion-pump management software contains multiple critical, remotely exploitable vulnerabilities—hard-coded database/passwords and cryptographic keys, cleartext installer credentials, and a JBoss-based remote code execution flaw (CVSS 10)—that could allow attackers to compromise MedNet servers and alter pump configurations; Hospira released MedNet 6.1 and mitigations, and no public exploits were reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
