Security readout for executives and security teams
Plain-English summary
Hospira LifeCare PCA Infusion System version 5 stores wireless keys in plain text. If those keys are obtained, wireless access controls could be weakened around clinical infusion equipment. The source bundle does not provide CVSS, active exploitation evidence, or detailed impact beyond credential exposure.
Executive priority
Treat this as a medical-device credential exposure risk requiring asset confirmation and upgrade planning. Urgency depends on whether affected wireless-capable devices remain deployed. Because no exploitation evidence or CVSS is provided, prioritize validation before emergency action.
Technical view
This is a CWE-312 cleartext storage issue affecting Hospira LifeCare PCA Infusion System versions listed as <=5.0. Hospira stated version 3 was not intended or shipped for wireless use, and version 7.0 addresses identified vulnerabilities, including closing FTP and Telnet by default.
Likely exposure
Exposure is most likely in healthcare environments still operating LifeCare PCA systems at version 5.0 or earlier, especially units configured or modified for wireless capability. Version 3 wireless use should be treated as unsupported per Hospira’s statement.
Exploitation context
The bundle shows no CISA KEV listing and no cited evidence of active exploitation. The known issue is local storage of wireless keys in plain text, which may matter if an unauthorized party gains access to the device or its configuration storage.
Researcher notes
Evidence is limited to the CVE description and the ICS-CERT reference. The affected record lists <=5.0, while the description specifically names version 5 and separately discusses unsupported wireless use on version 3. Avoid expanding impact beyond cleartext wireless key storage without vendor advisory details.
Mitigation direction
- Inventory LifeCare PCA devices and confirm software version and wireless configuration.
- Prioritize upgrade planning to Hospira version 7.0 where clinically and operationally approved.
- Do not modify version 3 systems for wireless clinical use.
- Confirm FTP port 20 and Telnet port 23 are closed on upgraded systems.
- Check Hospira and clinical engineering guidance before operational changes.
Validation and detection
- Confirm whether any LifeCare PCA version <=5.0 remains deployed.
- Document whether deployed units use or expose wireless capability.
- Verify version 3 devices have not been modified for wireless clinical use.
- Check upgraded systems for version 7.0 configuration expectations.
- Record compensating controls and vendor guidance in asset risk notes.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-312: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2015-1012 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://ics-cert.us-cert.gov/advisories/ICSA-15-125-01CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Cleartext Storage of Sensitive Information
Cleartext Storage of Sensitive Information represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
