LiveActive security incident?Get immediate response
CVE Record

CVE-2015-1012: Wireless keys are stored in plain text on version 5 of the Hospira LifeCare PCA Infusion System.

Wireless keys are stored in plain text on version 5 of the Hospira LifeCare PCA Infusion System. According to Hospira, version 3 of the LifeCare PCA Infusion System is not indicated for wireless use, is not shipped with wireless capabilities, and should not be modified to be used in a wireless capacity in a clinical setting. Hospira has developed a new version of the PCS Infusion System, version 7.0 that addresses the identified vulnerabilities. Version 7.0 has Port 20/FTP and Port 23/TELNET closed by default to prevent unauthorized access.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

Hospira LifeCare PCA Infusion System version 5 stores wireless keys in plain text. If those keys are obtained, wireless access controls could be weakened around clinical infusion equipment. The source bundle does not provide CVSS, active exploitation evidence, or detailed impact beyond credential exposure.

Executive priority

Treat this as a medical-device credential exposure risk requiring asset confirmation and upgrade planning. Urgency depends on whether affected wireless-capable devices remain deployed. Because no exploitation evidence or CVSS is provided, prioritize validation before emergency action.

Technical view

This is a CWE-312 cleartext storage issue affecting Hospira LifeCare PCA Infusion System versions listed as <=5.0. Hospira stated version 3 was not intended or shipped for wireless use, and version 7.0 addresses identified vulnerabilities, including closing FTP and Telnet by default.

Likely exposure

Exposure is most likely in healthcare environments still operating LifeCare PCA systems at version 5.0 or earlier, especially units configured or modified for wireless capability. Version 3 wireless use should be treated as unsupported per Hospira’s statement.

Exploitation context

The bundle shows no CISA KEV listing and no cited evidence of active exploitation. The known issue is local storage of wireless keys in plain text, which may matter if an unauthorized party gains access to the device or its configuration storage.

Researcher notes

Evidence is limited to the CVE description and the ICS-CERT reference. The affected record lists <=5.0, while the description specifically names version 5 and separately discusses unsupported wireless use on version 3. Avoid expanding impact beyond cleartext wireless key storage without vendor advisory details.

Mitigation direction

  • Inventory LifeCare PCA devices and confirm software version and wireless configuration.
  • Prioritize upgrade planning to Hospira version 7.0 where clinically and operationally approved.
  • Do not modify version 3 systems for wireless clinical use.
  • Confirm FTP port 20 and Telnet port 23 are closed on upgraded systems.
  • Check Hospira and clinical engineering guidance before operational changes.

Validation and detection

  • Confirm whether any LifeCare PCA version <=5.0 remains deployed.
  • Document whether deployed units use or expose wireless capability.
  • Verify version 3 devices have not been modified for wireless clinical use.
  • Check upgraded systems for version 7.0 configuration expectations.
  • Record compensating controls and vendor guidance in asset risk notes.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-312: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2015-1012 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
HospiraLifeCare PCA Infusion System<= 5.0Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-312 · source CWE mapping

Cleartext Storage of Sensitive Information

Cleartext Storage of Sensitive Information represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.