VYPR

Plum A+ Infusion System

by Hospira

CVEs (5)

  • CVE-2015-3956Mar 25, 2019
    risk 0.00cvss epss 0.01

    Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior accept drug libraries, firmware updates, pump commands, and unauthorized configuration changes from unauthenticated devices…

  • CVE-2015-3954Mar 25, 2019
    risk 0.00cvss epss 0.02

    Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior give unauthenticated users root privileges on Port 23/TELNET by default. An unauthorized user could issue commands to the…

  • CVE-2015-3953Mar 25, 2019
    risk 0.00cvss epss 0.02

    Hard-coded accounts may be used to access Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends that customers close Port 20/FTP and Port 23/TELNET on the…

  • CVE-2015-3952Mar 25, 2019
    risk 0.00cvss epss 0.01

    Wireless keys are stored in plain text on Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends that customers close Port 20/FTP and Port 23/TELNET on the…

  • CVE-2015-3965Mar 23, 2019
    risk 0.00cvss epss 0.03

    Hospira Symbiq Infusion System 3.13 and earlier allows remote authenticated users to trigger "unanticipated operations" by leveraging "elevated privileges" for an unspecified call to an incorrectly exposed function.