Hospira LifeCare PCA Infusion System
Published Jul 6, 2015
9.3
HIGHCVSS 2.0
EPSS 1.24%
Description
The Hospira LifeCare PCA Infusion System before 7.0 does not validate network traffic associated with sending a (1) drug library, (2) software update, or (3) configuration change, which allows remote attackers to modify settings or medication data via packets on the (a) TELNET, (b) HTTP, (c) HTTPS, or (d) UPNP port. NOTE: this issue might overlap CVE-2015-3459.
Affected products
-
- Version 0StatusaffectedConstraints<=5.0
- Version 7.0StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Hospira | LifeCare PCA Infusion System | unaffected |
|
- ≤ 5.0
Running on/with
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
ICS-CERT has been working with Hospira since May 2014 to address the vulnerabilities in the LifeCare PCA Infusion System. Hospira has developed a new version of the PCS Infusion System, Version 7.0 that addresses the identified vulnerabilities. According to Hospira, Version 7.0 has Port 20/FTP and Port 23/TELNET closed by default to prevent unauthorized access. Existing PCA Infusion Systems running Version 5.0 can be upgraded to Version 7.0 when it becomes available. Hospira’s Version 7.0 is being reviewed by the FDA prior to its release. The release date for Version 7.0 of the LifeCare PCA Infusion System has not been determined.
For additional information about Hospira’s new release, contact Hospira’s technical support at 1‑800-241-4002.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:C/I:C/A:C
1 other source (CVE.org) ▾
AV:N/AC:H/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.24% (0.01242) | 68.12th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.24% (0.01242) | 65.23th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.43% (0.00426) | 60.20th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.62% (0.00618) | 79.50th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.62% (0.00618) | 78.14th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.62% (0.00618) | 75.50th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.14% (0.01136) | 59.45th | v2 (v2022.01.01) |
| Oct 18, 2022 | 1.14% (0.01136) | 58.28th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.14% (0.01136) | 56.27th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.14% (0.01136) | 34.23th | v2 (v2022.01.01) |
References (5)
- http://www.fda.gov/MedicalDevices/Safety/AlertsandNotices/ucm446809.htm x_refsource_MISCThird Party AdvisoryUS Government Resource
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2015/icsa-15-125-01.json
- https://ics-cert.us-cert.gov/advisories/ICSA-15-125-01 Third Party AdvisoryUS Government Resource
- https://www.cisa.gov/news-events/ics-advisories/icsa-15-125-01
- https://xs-sniper.com/blog/2015/06/08/hospira-plum-a-infusion-pump-vulnerabilities/ x_refsource_MISC
| Link | Providers | Tags |
|---|---|---|
| http://www.fda.gov/MedicalDevices/Safety/AlertsandNotices/ucm446809.htm | x_refsource_MISCThird Party AdvisoryUS Government Resource | |
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2015/icsa-15-125-01.json | ||
| https://ics-cert.us-cert.gov/advisories/ICSA-15-125-01 | Third Party AdvisoryUS Government Resource | |
| https://www.cisa.gov/news-events/ics-advisories/icsa-15-125-01 | ||
| https://xs-sniper.com/blog/2015/06/08/hospira-plum-a-infusion-pump-vulnerabilities/ | x_refsource_MISC |
Change history (0)
No recorded changes yet.