logo

Researcher: Drug Pump the ‘Least Secure IP Device I’ve Ever Seen’

ID: f1d68ea9-f82e-5af6-b51b-2ceca48e6adc

STIX ID: report--f1d68ea9-f82e-5af6-b51b-2ceca48e6adc

Feed Name: Security Ledger

Threat Score
80/100

Date Published: 2015-05-05

Date Updated: 2026-05-08

Author: Paul Roberts

...
...

Hospira LifeCare PCA 3 infusion pumps were found to contain multiple critical security vulnerabilities — unauthenticated Telnet and FTP access granting root/admin shells, plaintext storage of wireless keys, CGI web-interface weaknesses, and lack of firmware update validation — that could allow an attacker with physical or network access to take full control of pumps; DHS/ICS-CERT warnings and a CVE (CVE-2015-3459) underscore the severity and potential patient-safety impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.