logo

For Industrial, Medical Systems: Bugs Run In The Family

ID: ee8ef4bc-7f2d-576a-826a-932ee8ec0f0a

STIX ID: report--ee8ef4bc-7f2d-576a-826a-932ee8ec0f0a

Feed Name: Security Ledger

Threat Score
70/100

Date Published: 2013-01-17

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

Researchers Billy Rios and Terry McCorkle presented findings that many medical devices from major manufacturers (including Philips, GE, Siemens, Honeywell) share critical software security flaws similar to industrial control systems—examples include heap overflows triggered by network services, documented backdoor administrator accounts with weak PINs, and insecure credential storage allowing remote RDP-based access; these issues could enable remote unauthenticated compromise of patient monitoring systems and pose direct risks to patient safety. The researchers reported the findings to DHS ICS-CERT, while vendors such as Philips stated they have product security programs, prompting questions about why such obvious flaws were missed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.