Researchers from CyberMDX, a healthcare security company , have discovered vulnerabilities in two anesthesia delivery devices used in hospitals and manufactured by General Electric (GE).
The two vulnerable devices are the GE Aestiva and GE Aespire (models 7100 and 7900). According to the researchers , the vulnerabilities were found in the devices' firmware
Vulnerabilities can put patients at risk
CyberMDX said that when attackers are on the same network as the devices (in this case, a hospital network), they can exploit the vulnerabilities and send commands, remotely, to change the devices' settings.
A researcher said that these commands are supported by the design of the device. Some are only supported in an older version of the protocol, but there is another command that allows the protocol version to be changed. If the attacker does this, then he will be able to send all the other commands.
Thus, attackers can make various changes that could endanger patients. They could, for example, change the gas composition in the machines (e.g., modify the concentration of oxygen, CO2, N2O), silence the alarms of the devices so that they do not sound if there is a problem, modify the records with data and times, which show, for example, when an operation was performed and how it went.
These are all very serious issues, which endanger the lives of patients.

“Anesthesiology is a complex science and each patient may react differently to treatment. Therefore, anesthesiologists must follow strict protocols for the use of procedures, doses and many other elements.
To do their job, anesthesiologists need to know certain things precisely. If the time and date settings are violated, doctors cannot perform the necessary checks.
"This is a very serious problem for any medical center," the researcher said.
The most worrying thing is that these vulnerabilities are easy to exploit. All it takes is gaining access to the hospital network, which isn't too difficult, considering that most hospital networks and systems use old and insecure software.
What does GE say?
CyberMDX has reported the vulnerabilities to GE since October 2018. GE decided not to issue updates, but did post some advisories on website its.
GE said the vulnerabilities can be avoided if anesthesia devices are not connected to a hospital network. According to the company, the real vulnerabilities are found only in the communications protocols used when the devices' serial port (e.g. USB) is connected to a TCP/IP network. If the devices are not connected to the network, they cannot be used by hackers, even if they have gained access to the hospital network.
Additionally, GE said that the ability to modify the gas composition no longer exists on machines sold after 2009. Therefore, this risk no longer exists unless hospitals are using very old GE Aestiva and GE Aespire machines.
