CVE-2014-5401

CRITICAL

Hospira MedNet < 5.8 - Unauthenticated Remote Code Execution via JBoss Enterprise Application Platform

Title source: llm
STIX 2.1

Description

Hospira MedNet software version 5.8 and prior uses vulnerable versions of the JBoss Enterprise Application Platform software that may allow unauthenticated users to execute arbitrary code on the target system. Hospira has developed a new version of the MedNet software, MedNet 6.1. Existing versions of MedNet can be upgraded to MedNet 6.1.

Scores

CVSS v3 9.8
EPSS 0.0501
EPSS Percentile 91.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (1)
hospira/mednet < 5.8
Published Mar 26, 2019
Tracked Since Feb 18, 2026