ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Report: Nearly 75% of Infusion Pumps Affected by Severe Vulnerabilities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2016-9355
+1 in the same advisory: …8375
An issue was discovered in Becton, Dickinson and Company (BD) Alaris 8015 Point of Care (PC) unit, Version 9.5 and prior versions, and Version 9.7.

An issue was discovered in Becton, Dickinson and Company (BD) Alaris 8015 Point of Care (PC) unit, Version 9.5 and prior versions, and Version 9.7. An unauthorized user with physical access to an Alaris 8015 PC unit may be able to obtain unencrypted wireless network authentication credentials and other sensitive technical data by disassembling an Alaris 8015 PC unit and accessing the device's flash memory. Older software versions of the Alaris 8015 PC unit, Version 9.5 and prior versions, store wireless network authentication credentials and other sensitive technical data on the affected device's removable flash memory. Being able to remove the flash memory from the affected device reduces the risk of detection, allowing an attacker to extract stored data at the attacker's convenience.

NVD description · AI analysis pending
5.3
group max
<1%
  • bd alaris 8015 pc unit
CVE-2019-12255
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4).

Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow.

NVD description · AI analysis pending
9.875% PoC
  • windriver vxworks
  • windriver e-series santricity os controller
  • windriver sonicos
  • +1 more
CVE-2019-12264
Wind River VxWorks 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 has Incorrect Access Control in IPv4 assignment by the ipdhcpc DHCP client component.

Wind River VxWorks 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 has Incorrect Access Control in IPv4 assignment by the ipdhcpc DHCP client component.

NVD description · AI analysis pending
7.18%
  • windriver vxworks
  • windriver hirschmann hios
  • windriver garrettcom magnum dx940e firmware
  • +1 more
CVE-2020-12043
+4 in the same advisory: …12045 …12047 …12040 …12041
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when configured for wireless networking the FTP service operating on the WBM remains operation

The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when configured for wireless networking the FTP service operating on the WBM remains operational until the WBM is rebooted.

NVD description · AI analysis pending
9.8
group max
2%
  • baxter sigma spectrum infusion system firmware
CVE-2020-25165
BD Alaris PC Unit, Model 8015, Versions 9.33.1 and earlier and BD Alaris Systems Manager, Versions 4.33 and earlier The affected products are vulnerable to a ne

BD Alaris PC Unit, Model 8015, Versions 9.33.1 and earlier and BD Alaris Systems Manager, Versions 4.33 and earlier The affected products are vulnerable to a network session authentication vulnerability within the authentication process between specified versions of the BD Alaris PC Unit and the BD Alaris Systems Manager. If exploited, an attacker could perform a denial-of-service attack on the BD Alaris PC Unit by modifying the configuration headers of data in transit. A denial-of-service attack could lead to a drop in the wireless capability of the BD Alaris PC Unit, resulting in manual operation of the PC Unit.

NVD description · AI analysis pending
7.52%
  • bd alaris 8015 pcu firmware
  • bd alaris systems manager
Full article485 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananMar 03, 2022

An analysis of data crowdsourced from more than 200,000 network-connected infusion pumps used in hospitals and healthcare entities has revealed that 75% of those medical devices contain security weaknesses that could put them at risk of potential exploitation.

"These shortcomings included exposure to one or more of some 40 known cybersecurity vulnerabilities and/or alerts that they had one or more of some 70 other types of known security shortcomings for IoT devices," Unit 42 security researcher Aveek Das said in a report published Wednesday.

Palo Alto Networks' threat intelligence team said it obtained the scans from seven medical device manufacturers. On top of that, 52.11% of all infusion pumps scanned were susceptible to two known vulnerabilities that were disclosed in 2019 as part of 11 flaws collectively called "URGENT/11" –

  • CVE-2019-12255 (CVSS score: 9.8) – A buffer overflow flaw in the TCP component of Wind River VxWorks
  • CVE-2019-12264 (CVSS score: 7.1) – An issue with incorrect access control in the DHCP client component of Wind River VxWorks

Other important flaws impacting infusion pumps are listed below –

  • CVE-2016-9355 (CVSS score: 5.3) – An unauthorized user with physical access to an Alaris 8015 Point of Care units may be able to disassemble the device to access the removable flash memory, allowing read-and-write access to device memory
  • CVE-2016-8375 (CVSS score: 4.9) – A credential management error in Alaris 8015 Point of Care units that could be exploited to gain unencrypted wireless network authentication credentials and other sensitive technical data
  • CVE-2020-25165 (CVSS score: 7.5) – An improper session authentication vulnerability in Alaris 8015 Point of Care units that could be abused to perform a denial-of-service attack on the devices
  • CVE-2020-12040 (CVSS score: 9.8) – Cleartext transmission of sensitive information in Sigma Spectrum Infusion System
  • CVE-2020-12047 (CVSS score: 9.8) – Use of hard-coded FTP credentials in Baxter Spectrum WBM
  • CVE-2020-12045 (CVSS score: 9.8) – Use of hard-coded Telnet credentials in Baxter Spectrum WBM
  • CVE-2020-12043 (CVSS score: 9.8) – Baxter Spectrum WBM FTP service remains operational after its expected expiry time until it's rebooted
  • CVE-2020-12041 (CVSS score: 9.8) – Baxter Spectrum Wireless Battery Module (WBM) permits data transmission and command-line interfaces over Telnet

Successful exploitation of the aforementioned vulnerabilities could result in leakage of sensitive information pertaining to patients and allow an attacker to gain unauthorized access to the devices, necessitating that health systems are proactively protected against threats.

Last year, McAfee disclosed security vulnerabilities affecting B. Braun's Infusomat Space Large Volume Pump and SpaceStation that could be abused by malicious parties to tamper with medication doses without any prior authentication.

The discovery "highlights the need for the healthcare industry to redouble efforts to protect against known vulnerabilities, while diligently following best practices for infusion pumps and hospital networks," Das said.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/03/report-nearly-75-of-infusion-pumps.html