CVE-2015-3965

Hospira Symbiq Infusion System 3.13 and earlier allows remote authenticated users to trigger "unanticipated operations" by leveraging "elevated privileges" for an unspecified call to an incorrectly exposed function.
References
Link Resource
https://ics-cert.us-cert.gov/advisories/ICSA-15-174-01 Third Party Advisory US Government Resource
https://ics-cert.us-cert.gov/advisories/ICSA-15-174-01 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:pfizer:symbiq_infusion_system_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:pfizer:symbiq_infusion_system:-:*:*:*:*:*:*:*

History

21 Nov 2024, 02:30

Type Values Removed Values Added
References () https://ics-cert.us-cert.gov/advisories/ICSA-15-174-01 - US Government Resource, Third Party Advisory () https://ics-cert.us-cert.gov/advisories/ICSA-15-174-01 - Third Party Advisory, US Government Resource

Information

Published : 2019-03-23 20:29

Updated : 2024-11-21 02:30


NVD link : CVE-2015-3965

Mitre link : CVE-2015-3965

CVE.ORG link : CVE-2015-3965


JSON object : View

Products Affected

pfizer

  • symbiq_infusion_system
  • symbiq_infusion_system_firmware
CWE
CWE-264

Permissions, Privileges, and Access Controls