HomeSecurityOver 100 GE Healthcare devices vulnerable to critical vulnerability

Over 100 GE Healthcare devices vulnerable to critical vulnerability

According to security firm CyberMDX, over 100 devices GE Healthcare vulnerability that could allow an attacker to access or even modify health information (PHI).

 GE Healthcare

The vulnerability has been named CVE-2020-25179 and is rated critical. According to the researchers, it affects: CT scanners, molecular imaging, PET, X-ray, ultrasound and mammography devices, as well as workstations and imaging devices used in surgical procedures. The GE Healthcare products affected are: Brivo, Definium, Discovery, Innova, Optima, Odyssey, PETtrace, Precision, Seno, Revolution, Ventri and Xeleris.

However, GE Healthcare stated that no unauthorized access to data and there is no evidence that this vulnerability has already been used by criminals.

“We conducted a full risk assessment and concluded that there is no patient safety issue. Maintaining the safety and quality of our devices is our highest priority,” the company said.

The issue discovered by CyberMDX researchers is related to the presence of hardcoded credentials for GE Healthcare management software. The credentials can be found online and are used by update and maintenance software to control connections to GE servers.

Over 100 GE Healthcare devices vulnerable to critical vulnerability

An attacker with network access to a targeted device could misuse these credentials (which are the same worldwide) to gain access to health information (PHI) and other sensitive data. In addition, according to the researchers, the attacker could modify the exposed data, execute code on the system, or cause the system to malfunction.

The hardcoded credentials can only be changed by GE Healthcare. Users are not able to modify them. However, the medical device maker says it is providing assistance to ensure that the credentials are changed and that the product's firewall is configured correctly. According to GE Healthcare, no patch to address the vulnerability, but organizations for security and network management.

GE Healthcare says that exploiting the vulnerability is not that easy for criminals, as they would first have to gain access to systems protected by various security and firewalls. Furthermore, even if they were able to exploit the flaw, they would not find much health information, as only a limited amount of PHI is stored on the imaging devices themselves, and only temporarily. The data is typically sent directly to the PACS archiving system and stored there.

However, Elad Luz, head of research at CyberMDX, pointed out that hospital networks are breached quite frequently, so hackers may not have that much difficulty gaining access.

CISA warned organizations using vulnerable medical devices from GE Healthcare.

Source: Security Week

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS