ID

VAR-201507-0391


CVE

CVE-2015-3958


TITLE

Hospira LifeCare PCA Infusion System Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2015-003458

DESCRIPTION

Hospira LifeCare PCA Infusion System 5.0 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (forced manual reboot) via a flood of TCP packets. Supplementary information : CWE Vulnerability type by CWE-19: Data Handling ( Data processing ) Has been identified. Multiple Hospira products are prone to a remote denial-of-service vulnerability. An attacker can exploit this issue to cause a denial-of-service condition. Hospira LifeCare PCA Infusion System is an intelligent infusion system developed by Hospira in the United States. A security vulnerability exists in Hospira LifeCare PCA Infusion System 5.0 and earlier

Trust: 1.98

sources: NVD: CVE-2015-3958 // JVNDB: JVNDB-2015-003458 // BID: 75138 // VULHUB: VHN-81919

AFFECTED PRODUCTS

vendor:hospiramodel:lifecare pcainfusionscope:lteversion:5.0

Trust: 1.0

vendor:hospiramodel:lifecare pca infusion systemscope:lteversion:5.0

Trust: 0.8

vendor:hospiramodel:lifecare pca3scope: - version: -

Trust: 0.8

vendor:hospiramodel:lifecare pca5scope: - version: -

Trust: 0.8

vendor:hospiramodel:lifecare pcainfusionscope:eqversion:5.0

Trust: 0.6

sources: JVNDB: JVNDB-2015-003458 // CNNVD: CNNVD-201506-435 // NVD: CVE-2015-3958

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-3958
value: HIGH

Trust: 1.0

NVD: CVE-2015-3958
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201506-435
value: HIGH

Trust: 0.6

VULHUB: VHN-81919
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2015-3958
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-81919
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-81919 // JVNDB: JVNDB-2015-003458 // CNNVD: CNNVD-201506-435 // NVD: CVE-2015-3958

PROBLEMTYPE DATA

problemtype:CWE-19

Trust: 1.1

problemtype:CWE-Other

Trust: 0.8

sources: VULHUB: VHN-81919 // JVNDB: JVNDB-2015-003458 // NVD: CVE-2015-3958

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201506-435

TYPE

Failure to Handle Exceptional Conditions

Trust: 0.3

sources: BID: 75138

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-003458

PATCH

title:LifeCare PCA Infusion Systemurl:http://www.hospira.com/en/products_and_services/infusion_pumps/Lifecare/

Trust: 0.8

sources: JVNDB: JVNDB-2015-003458

EXTERNAL IDS

db:NVDid:CVE-2015-3958

Trust: 2.8

db:ICS CERTid:ICSA-15-125-01B

Trust: 2.5

db:BIDid:75138

Trust: 2.0

db:JVNDBid:JVNDB-2015-003458

Trust: 0.8

db:CNNVDid:CNNVD-201506-435

Trust: 0.7

db:VULHUBid:VHN-81919

Trust: 0.1

sources: VULHUB: VHN-81919 // BID: 75138 // JVNDB: JVNDB-2015-003458 // CNNVD: CNNVD-201506-435 // NVD: CVE-2015-3958

REFERENCES

url:http://www.fda.gov/medicaldevices/safety/alertsandnotices/ucm446809.htm

Trust: 2.5

url:https://ics-cert.us-cert.gov/advisories/icsa-15-125-01b

Trust: 2.5

url:http://www.securityfocus.com/bid/75138

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-3958

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-3958

Trust: 0.8

sources: VULHUB: VHN-81919 // JVNDB: JVNDB-2015-003458 // CNNVD: CNNVD-201506-435 // NVD: CVE-2015-3958

CREDITS

Billy Rios

Trust: 0.9

sources: BID: 75138 // CNNVD: CNNVD-201506-435

SOURCES

db:VULHUBid:VHN-81919
db:BIDid:75138
db:JVNDBid:JVNDB-2015-003458
db:CNNVDid:CNNVD-201506-435
db:NVDid:CVE-2015-3958

LAST UPDATE DATE

2025-04-13T23:09:18.777000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-81919date:2016-12-06T00:00:00
db:BIDid:75138date:2015-07-15T00:29:00
db:JVNDBid:JVNDB-2015-003458date:2015-07-09T00:00:00
db:CNNVDid:CNNVD-201506-435date:2015-07-07T00:00:00
db:NVDid:CVE-2015-3958date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:VULHUBid:VHN-81919date:2015-07-06T00:00:00
db:BIDid:75138date:2015-06-11T00:00:00
db:JVNDBid:JVNDB-2015-003458date:2015-07-09T00:00:00
db:CNNVDid:CNNVD-201506-435date:2015-06-24T00:00:00
db:NVDid:CVE-2015-3958date:2015-07-06T19:59:04.363