CVE-2014-5403

Hospira MedNet before 6.1 uses hardcoded cryptographic keys for protection of data transmission from infusion pumps, which allows remote attackers to obtain sensitive information by sniffing the network.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hospira:mednet:*:*:*:*:*:*:*:*

History

03 Nov 2025, 19:15

Type Values Removed Values Added
References
  • () https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2015/icsa-15-090-03.json -
  • () https://www.cisa.gov/news-events/ics-advisories/icsa-15-090-03 -
CWE CWE-321
CVSS v2 : 5.0
v3 : unknown
v2 : 6.8
v3 : unknown

Information

Published : 2015-04-03 10:59

Updated : 2025-11-03 19:15


NVD link : CVE-2014-5403

Mitre link : CVE-2014-5403

CVE.ORG link : CVE-2014-5403


JSON object : View

Products Affected

hospira

  • mednet
CWE
CWE-321

Use of Hard-coded Cryptographic Key

CWE-310

Cryptographic Issues