Vulnerabilities > CVE-2014-5420 - Credentials Management vulnerability in Carefusion Pyxis Supplystation 8.1

047910
CVSS 3.5 - LOW
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE

Summary

CareFusion Pyxis SupplyStation 8.1 with hardware test tool before 1.0.16 has a hardcoded application password, which makes it easier for remote authenticated users to obtain application-file access via unspecified vectors.

Vulnerable Configurations

Part Description Count
Hardware
Carefusion
1

Common Weakness Enumeration (CWE)