{"id":9271,"date":"2017-09-13T09:10:03","date_gmt":"2017-09-13T17:10:03","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/09\/13\/news-3044\/"},"modified":"2017-09-13T09:10:03","modified_gmt":"2017-09-13T17:10:03","slug":"news-3044","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2017\/09\/13\/news-3044\/","title":{"rendered":"Multiple flaws found in smart syringe pump"},"content":{"rendered":"<p><strong>Credit to Author: Malwarebytes Labs| Date: Wed, 13 Sep 2017 16:27:50 +0000<\/strong><\/p>\n<p>A syringe pump\u00a0is a small infusion pump that delivers liquids, either medication or nutrients, in small quantities into the patient&#8217;s system. Hospitals, nursing homes, and homes with residents\u00a0under acute or palliative care use them. Accurate and safe delivery of dosage from a variety of syringes make such a device essential. Unfortunately, a particular model of a wireless smart pump is found to be so vulnerable that a malicious, highly skilled attacker can compromise its communications and therapeutic modules, which in turn could also compromise\u00a0a patient&#8217;s well-being.<\/p>\n<p>Late last week, the Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) released <a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSMA-17-250-02\" target=\"_blank\" rel=\"noopener\">an advisory for the Medfusion 4000 Wireless Syringe Infusion Pump<\/a> after Scott Gayou, an independent security researcher, brought to light multiple vulnerabilities in the device that can be exploited remotely.<\/p>\n<p>According to Gayou, the said syringe pump has problems with the way it processes data, which could then lead to either the unauthorized execution of code or a system crash. He also pointed out that several credentials are hard-coded to the pump, with some even accessible to anyone if the pump&#8217;s communication module is modified. Furthermore, the pump is incapable of validating certificates, making it a good candidate for <a href=\"https:\/\/blog.malwarebytes.com\/glossary\/man-in-the-middle-mitm\/\" target=\"_blank\" rel=\"noopener\">MiTM attacks<\/a>, allowing threat actors to bypass any security measures in place and gain elevated privileges on it.<\/p>\n<p>Medfusion 4000 Wireless Syringe Infusion Pump versions 1.1, 1.5, and 1.6 are affected by these vulnerabilities.<\/p>\n<p>Smiths Medical, makers of the said smart pump, has announced that they&#8217;ll be releasing\u00a0version 1.6.1 of the product to address the vulnerabilities above. In the meantime, ICS-CERT has\u00a0advised users of the Medfusion 4000 syringe pump to take steps to lessen the possibility of exploitation. One advice\u00a0is to disconnect the pump from the internet altogether.<\/p>\n<p><span style=\"background-color: #f5f6f5\">Smiths Medical and\u00a0ICS-CERT provided\u00a0<\/span>more mitigation steps in <a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSMA-17-250-02\" rel=\"noopener\">this advisory<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<p><em>The Malwarebytes Labs Team<\/em><\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/security-world\/2017\/09\/multiple-flaws-found-in-smart-syringe-pump\/\">Multiple flaws found in smart syringe pump<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/security-world\/2017\/09\/multiple-flaws-found-in-smart-syringe-pump\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Malwarebytes Labs| Date: Wed, 13 Sep 2017 16:27:50 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/security-world\/2017\/09\/multiple-flaws-found-in-smart-syringe-pump\/' title='Multiple flaws found in smart syringe pump'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/09\/shutterstock_571617352.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>As more life-saving medical devices are capable of connecting to the internet, the potential threat of malicious hacking leading to physical bodily harm becomes more real. An independent researcher recently found multiple vulnerabilities plaguing a particular syringe pump.\u00a0ICS-CERT offers several defensive measures.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/security-world\/\" rel=\"category tag\">Security world<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/security-world\/technology\/\" rel=\"category tag\">Technology<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/iot\/\" rel=\"tag\">IoT<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/iot-threats\/\" rel=\"tag\">iot threats<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/medfusion-4000-wireless-syringe-infusion-pump\/\" rel=\"tag\">Medfusion 4000 Wireless Syringe Infusion Pump<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/medical-device\/\" rel=\"tag\">medical device<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/medical-device-threat\/\" rel=\"tag\">medical device threat<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/smart-syringe-pump\/\" rel=\"tag\">smart syringe pump<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/syringe-pump-vulnerability\/\" rel=\"tag\">syringe pump vulnerability<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/security-world\/2017\/09\/multiple-flaws-found-in-smart-syringe-pump\/' title='Multiple flaws found in smart syringe pump'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/security-world\/2017\/09\/multiple-flaws-found-in-smart-syringe-pump\/\">Multiple flaws found in smart syringe pump<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[10495,14722,14723,14724,14725,10497,14726,14727,1331],"class_list":["post-9271","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-iot","tag-iot-threats","tag-medfusion-4000-wireless-syringe-infusion-pump","tag-medical-device","tag-medical-device-threat","tag-security-world","tag-smart-syringe-pump","tag-syringe-pump-vulnerability","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/9271","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=9271"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/9271\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=9271"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=9271"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=9271"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}