Hospira MedNet before 6.1 uses a hardcoded cleartext password to control SQL database authorization, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password.Referenceshttps://ics-cert.us-cert.gov/advisories/ICSA-15-090-03