Researcher: Drug Pump the ‘Least Secure IP Device I’ve Ever Seen’
ID: f1d68ea9-f82e-5af6-b51b-2ceca48e6adc
STIX ID: report--f1d68ea9-f82e-5af6-b51b-2ceca48e6adc
Feed Name: Security Ledger
Threat Score
Hospira LifeCare PCA 3 infusion pumps were found to contain multiple critical security vulnerabilities — unauthenticated Telnet and FTP access granting root/admin shells, plaintext storage of wireless keys, CGI web-interface weaknesses, and lack of firmware update validation — that could allow an attacker with physical or network access to take full control of pumps; DHS/ICS-CERT warnings and a CVE (CVE-2015-3459) underscore the severity and potential patient-safety impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
