US-CERT Issues Advisory About Vulnerabilities in Patient Monitors

Robinson+Cole Data Privacy + Security Insider
Contact

The U.S. Department of Homeland Security Industrial Control Systems Cyber Emergency Team (US-CERT) recently issued an advisory outlining three vulnerabilities of Drager Infinity Delta patient monitoring devices.

The vulnerabilities affect all versions of the Drager models—Delta, Delta XL, Kappa, and infinity Explorer C700—patient monitoring devices. According to the alert, the three security flaws include:

  • Exposure of Information in Log Files—the log files are not secured and can be accessed over an unauthenticated network, which allows an attacker to gain access to the log files and view the sensitive information contained in the logs, including the location of the device, the internal information of the monitor and its network configuration
  • Improper Input Validation—a flaw in the manner in which input is validated can be exploited to cause the monitor to reboot constantly until it reverts to the default configuration causing network connectivity to be lost
  • Privilege Escalation Through Improper Privilege Management—this vulnerability allows the attacker to gain access to the operating system and take full control of it.

Drager issued patches for the vulnerabilities in December 2018. According to the alert, users should update the devices to the newest version which is accessible through Drager ServiceConnect, review their network segmentation configuration to affirm that devices are separated from the hospital LAN system and confirm the Windows patch level on the Infinity Explorer is up to date.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Robinson+Cole Data Privacy + Security Insider | Attorney Advertising

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide