Evidence used
- No CISA KEV confirmation is currently recorded.
- EPSS is 1.24% for the current model date.
BlackTreeCVE IntelligenceHospira · LifeCare PCA Infusion System
High technical severity; prioritise exposed affected systems while verifying vendor guidance.
High technical severity; prioritise exposed affected systems while verifying vendor guidance.
Patch availableThe Hospira LifeCare PCA Infusion System before 7.0 does not validate network traffic associated with sending a (1) drug library, (2) software update, or (3) configuration change, which allows remote attackers to modify settings or medication data via packets on the (a) TELNET, (b) HTTP, (c) HTTPS, or (d) UPNP port. NOTE: this issue might overlap CVE-2015-3459.
The Hospira LifeCare PCA Infusion System before 7.0 does not validate network traffic associated with sending a (1) drug library, (2) software update, or (3) configuration change, which allows remote attackers to modify settings or medication data via packets on the (a) TELNET, (b) HTTP, (c) HTTPS, or (d) UPNP port. NOTE: this issue might overlap CVE-2015-3459.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
An attacker operating through the affected interface may attempt exploitation when the stated preconditions are met. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.
The Hospira LifeCare PCA Infusion System before 7.0 does not validate network traffic associated with sending a (1) drug library, (2) software update, or (3) configuration change, which allows remote attackers to modify settings or medication data via packets on the (a) TELNET, (b) HTTP, (c) HTTPS, or (d) UPNP port. NOTE: this issue might overlap CVE-2015-3459.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
An attacker operating through the affected interface may attempt exploitation when the stated preconditions are met. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.
CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.
No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.
No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.
CWE-345: Insufficient Verification of Data Authenticity. The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
AV:N/AC:H/Au:N/C:C/I:C/A:COperational remediation based on structured source evidence.
Published 6 Jul 2015 · Last source change 3 Nov 2025, 18:34 UTC · CWE-345 · Insufficient Verification of Data Authenticity
Core structured fields are present and their contributing authorities are shown above.