According to data collected from more than 200,000 network‑connected infusion pumps, which are used to deliver medication and fluids to patients, 75% of them operate with known security issues that could be exploited by malicious users.

See also: Android Joker malware steals data through 7 apps - Delete immediately!
The findings reveal that tens of thousands of devices are vulnerable to six critical‑severity defects (9.8 out of 10) reported in 2019 and 2020.
Using data collected from customers, researchers at Palo Alto Networks analyzed the security posture of more than 200,000 infusion pumps and found that at least 100,000 of them are vulnerable to critical security issues.
The most widespread critical bug encountered is CVE-2019-12255 , a memory corruption bug in the VxWorks real-time operating system (RTOS) , used for embedded devices, including infusion pump systems.
According to data from Palo Alto Networks, the flaw is present in 52% of infusion pumps studied, which translates to more than 104,000 devices.
See also: The CIA is secretly collecting data on Americans!
CVE -2019-12255 is part of a series of 11 vulnerabilities discovered and reported in 2019 by researchers at Armis, a company that provides security for connected devices.

Wind Riverhas addressed all issues in patches available since July 19, 2019. However, massive delays in applying updates or not installing them are known problems in the embedded device landscape.
The remaining five critical bugs affect products from US healthcare company Baxter International and were reported in June 2020.
There are no patches available for these vulnerabilities, but Baxter has provided a number of mitigations designed to reduce the risk of their exploitation and recommended migrating to the newer Spectrum IQ Infusion that is not affected by the above issues.
See also: DPD Group: Flaw in parcel tracking exposes customer data
In a recent post, Palo Alto Networks recommends that healthcare providers adopt a proactive security strategy to protect devices from known and unknown threats, which starts with an accurate inventory of all systems on the network.
The researchers note that not all vulnerabilities currently affecting infusion pumps are practical for remote attacks, but they pose a "risk to the overall security of healthcare organizations and patient safety."
