Hospira MedNet Code Injection
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 10epss 5.0%
exploitation probability
5.0%top 9% of all CVEs
observed exploitation
nono source reports it
Hospira MedNet software version 5.8 and prior uses vulnerable versions of the JBoss Enterprise Application Platform software that may allow unauthenticated users to execute arbitrary code on the target system. Hospira has developed a new version of the MedNet software, MedNet 6.1. Existing versions of MedNet can be upgraded to MedNet 6.1.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected products
Hospira · MedNet