Developers: | Cybersecurity and Infrastructure Security Agency (CISA) |
Date of the premiere of the system: | June, 2020 |
Branches: | Pharmaceutics, medicine, health care |
2020: U.S. authorities warned about easy remote cracking of the infusional Baxter and B systems. Braun
At the end of June, 2020 The agency of the USA on cyber security and protection of infrastructure (CISA) warned users that the infusional systems Baxter both B.Braun are badly protected and can become an easy target for hackers.
According to the statement of CISA, vulnerability of an IP stack of production Treck allow malefactors to get far off into a system and to receive control over it. Among the affected companies there were B. Braun, Baxter, Green Hills Software and CareStream. CISA recommended to users and administrators to wait for the additional information and special means of protecting. Besides, the companies promise to update the software for elimination of vulnerabilities.
B. Announced Braun vulnerabilities in third-party software which is used for network interaction in the system of the infusional pumps Outlook 400ES. The company received 30 patches from Treck software developer for elimination of vulnerabilities, but 20 of them are not applicable to the Outlook 400 ES platform. So far B. Braun does not advise clients to take any actions.
According to the statement of Baxter company, a problem concern also five versions of wireless battery modules of the infusional Baxter Spectrum system. The company already takes necessary steps for fault recovery. Baxter also recommends to isolate the infusional Spectrum systems in separate network to reduce the probability of the adjacent attack. Besides, the company recommended to use the relevant protocols of security of a wireless network.
It is said in the statement of Green Hills that the IP stack of GHnet v2 was developed on the basis of Treck stack. Green Hills added new features and corrected errors. The company considers that these improvements reduced risk of the hacker attack. Green Hills also promises to release corrections for other clients.[1]