CVE-2014-5401

CRITICAL

Hospira Mednet < 5.8 - Code Injection

Title source: rule
STIX 2.1

Description

Hospira MedNet software version 5.8 and prior uses vulnerable versions of the JBoss Enterprise Application Platform software that may allow unauthenticated users to execute arbitrary code on the target system. Hospira has developed a new version of the MedNet software, MedNet 6.1. Existing versions of MedNet can be upgraded to MedNet 6.1.

Scores

CVSS v3 9.8
EPSS 0.0168
EPSS Percentile 82.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (1)
hospira/mednet < 5.8
Published Mar 26, 2019
Tracked Since Feb 18, 2026