hospira CVE Vulnerabilities & Metrics

Focus on hospira vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About hospira Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with hospira. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total hospira CVEs: 11
Earliest CVE date: 03 Apr 2015, 10:59 UTC
Latest CVE date: 26 Mar 2019, 17:29 UTC

Latest CVE reference: CVE-2014-5401

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical hospira CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 7.3

Max CVSS: 10.0

Critical CVEs (≥9): 5

CVSS Range vs. Count

Range Count
0.0-3.9 1
4.0-6.9 3
7.0-8.9 2
9.0-10.0 5

CVSS Distribution Chart

Top 5 Highest CVSS hospira CVEs

These are the five CVEs with the highest CVSS scores for hospira, sorted by severity first and recency.

All CVEs for hospira

CVE-2014-5401 hospira vulnerability CVSS: 10.0 26 Mar 2019, 17:29 UTC

Hospira MedNet software version 5.8 and prior uses vulnerable versions of the JBoss Enterprise Application Platform software that may allow unauthenticated users to execute arbitrary code on the target system. Hospira has developed a new version of the MedNet software, MedNet 6.1. Existing versions of MedNet can be upgraded to MedNet 6.1.

CVE-2015-7909 hospira vulnerability CVSS: 7.5 22 Jan 2016, 11:59 UTC

Stack-based buffer overflow in Hospira Communication Engine (CE) before 1.2 in LifeCare PCA Infusion System 5.07, Plum A+ Infusion System 13.40, and Plum A+3 Infusion System 13.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via traffic on TCP port 5000.

CVE-2015-3958 hospira vulnerability CVSS: 7.8 06 Jul 2015, 19:59 UTC

Hospira LifeCare PCA Infusion System 5.0 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (forced manual reboot) via a flood of TCP packets.

CVE-2015-3957 hospira vulnerability CVSS: 4.6 06 Jul 2015, 19:59 UTC

Hospira LifeCare PCA Infusion System before 7.0 stores private keys and certificates, which has unspecified impact and attack vectors.

CVE-2015-3955 hospira vulnerability CVSS: 10.0 06 Jul 2015, 19:59 UTC

Stack-based buffer overflow in Hospira LifeCare PCA Infusion System 5.0 and earlier, and possibly other versions, allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2015-1011 hospira vulnerability CVSS: 5.0 06 Jul 2015, 19:59 UTC

Hospira LifeCare PCA Infusion System before 7.0 has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.

CVE-2014-5406 hospira vulnerability CVSS: 9.3 06 Jul 2015, 19:59 UTC

The Hospira LifeCare PCA Infusion System before 7.0 does not validate network traffic associated with sending a (1) drug library, (2) software update, or (3) configuration change, which allows remote attackers to modify settings or medication data via packets on the (a) TELNET, (b) HTTP, (c) HTTPS, or (d) UPNP port. NOTE: this issue might overlap CVE-2015-3459.

CVE-2015-3459 hospira vulnerability CVSS: 10.0 29 Apr 2015, 23:59 UTC

The communication module on the Hospira LifeCare PCA Infusion System before 7.0 does not require authentication for root TELNET sessions, which allows remote attackers to modify the pump configuration via unspecified commands.

CVE-2014-5405 hospira vulnerability CVSS: 9.0 03 Apr 2015, 10:59 UTC

Hospira MedNet before 6.1 uses a hardcoded cleartext password to control SQL database authorization, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password.

CVE-2014-5403 hospira vulnerability CVSS: 5.0 03 Apr 2015, 10:59 UTC

Hospira MedNet before 6.1 uses hardcoded cryptographic keys for protection of data transmission from infusion pumps, which allows remote attackers to obtain sensitive information by sniffing the network.

CVE-2014-5400 hospira vulnerability CVSS: 2.1 03 Apr 2015, 10:59 UTC

The installation component in Hospira MedNet before 6.1 places cleartext credentials in configuration files, which allows local users to obtain sensitive information by reading a file.