Breathe Deeply: DHS warns of Flaw in Hospital Anesthesia Machines
ID: 155755c2-b95c-5d0c-9186-064552d4e5ed
STIX ID: report--155755c2-b95c-5d0c-9186-064552d4e5ed
Feed Name: Security Ledger
Threat Score
GE Healthcare Aestiva and Aespire anesthesia machines (versions 7100 and 7900) contain a remotely exploitable software flaw that can be abused by an attacker on the same network—via terminal servers used to connect serial medical devices—to change gas composition parameters, alter device time, and mute alarms; CyberMDX notified GE and ICS-CERT in October 2018 and GE advises using secure terminal servers, network segmentation, firewalls, and device isolation to mitigate the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
