CVE-2014-5421

Published Oct 19, 2014

Last updated 10 years ago

Overview

Description
CareFusion Pyxis SupplyStation 8.1 with hardware test tool 1.0.16 and earlier has a hardcoded database password, which makes it easier for local users to gain privileges by leveraging cabinet access.
Source
ics-cert@hq.dhs.gov
NVD status
Analyzed

Risk scores

CVSS 2.0

Type
Primary
Base score
6.8
Impact score
9.5
Exploitability score
3.9
Vector string
AV:L/AC:L/Au:N/C:C/I:C/A:P

Weaknesses

nvd@nist.gov
CWE-255

Social media

Hype score
Not currently trending

Configurations