---
cve: "CVE-2014-5405"
severity: "CRITICAL"
cvss: 9.0
epss: "2.3%"
vendor: "Hospira"
kev: false
exploited: false
published: "2015-04-03 10:59:02"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-10-10T04:49:58+02:00"
---

# CVE-2014-5405

> 9.0 CRITICAL · 🧪 PoC

## Beschreibung

Hospira MedNet before 6.1 uses a hardcoded cleartext password to control SQL database authorization, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password.

## CVSS-Vektor

```
AV:N/AC:L/Au:S/C:C/I:C/A:C
```

## Referenzen

- <https://www.cisa.gov/news-events/ics-advisories/icsa-15-090-03>
- <https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2015/icsa-15-090-03.json>
- <https://ics-cert.us-cert.gov/advisories/ICSA-15-090-03>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/sicherheitsluecken/cve-2014-5405/) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
