Hospira MedNet Code Injection
Vulnerability Description
Hospira MedNet software version 5.8 and prior uses vulnerable versions of the JBoss Enterprise Application Platform software that may allow unauthenticated users to execute arbitrary code on the target system. Hospira has developed a new version of the MedNet software, MedNet 6.1. Existing versions of MedNet can be upgraded to MedNet 6.1.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-5401
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Billy Rios
References
More from Hospira
View All →Affected Vendor
Hospira
View all reports →