Embedded

Hospira Lifecare PCA infusion pump running “SW ver 412” does not require authentication for Telnet sessions, which allows remote attackers to gain root privileges via TCP port 23.

CVE-2015-3459

Sky

Eric Seidel, Dart Summit 2015, San Francisco, California

(demo)