CyberMDX Research Team Discovers Medical Device Vulnerability in GE Anesthesia and Respiratory Devices

FacebookFacebookTwitterTwitterEmailEmailLinkedInLinkedInWhatsAppWhatsAppMessengerMessengerFlipboardFlipboardGmailGmailTelegramTelegramShareShare

NEW YORK, July 9, 2019 /PRNewswire/ — A cyber vulnerability has been discovered in hospital anesthesia machines, the US Department of Homeland Security’s Industrial Control Systems – Cyber Emergency Response Team (ICS-CERT) disclosed today. The vulnerability, discovered by healthcare cybersecurity provider CyberMDX, could allow an attacker to impair respirator functionality, changing the composition of aspirated gases — silencing alarms, and altering time/date records. 

The CyberMDX research team found this vulnerability in the protocol of GE Aestiva and GE Aespire devices (models 7100 and 7900). Through the vulnerability, remote commands can be sent to interfere with the normal working order of the device.

If a malicious attacker can gain access to a hospital’s network and if the GE Aestiva and GE Aespire Devices are connected to a terminal server, the attacker can hack the devices without any prior knowledge of IP addresses or location of the machines. The attack could lead to unauthorized gas composition adjustments (altering the concentration of inspired/expired oxygen, CO2, N2O, and anesthetic agents), barometric pressure and anesthetic agent  manipulations,  alarm silencing, and out-of-process changes to date and time settings. If exploited, this vulnerability could directly impact the integrity, confidentiality, and availability of device components, while placing the patient at risk.

The vulnerability was given a CVSS value of 5.3 (reflecting moderate severity) in the ICS-CERT Advisory (ICSMA-19-190-01). The full report can be found at https://www.us-cert.gov/ics/advisories/icsma-19-190-01.  

“The potential for manipulating alarms and gas compositions is obviously troubling. More subtle but just as problematic is the ability to alter timestamps that reflect and document what happened in surgery. Anesthesiology is a complicated science and each patient may react differently to treatment. As such, Anesthesiologists must follow stringent protocols for documenting and reporting procedures, dosages, vital signs, and more. The ability to automatically and accurately capture these details is one of the main reasons why respirators are connected to the network to begin with. Once the integrity of time and date settings has been compromised, you no longer have reliable audit trails. That’s a very serious problem for any medical center,” said Elad Luz, Head of Research at CyberMDX.

More information on the vulnerability can be found on the CyberMDX website. 

About CyberMDX’s Cybersecurity Research & Analysis Team 
CyberMDX’s research and analyst team regularly works with medical device organizations in the responsible disclosure of security vulnerabilities. The threat intelligence team works tirelessly to help protect hospitals and healthcare organizations from malicious attacks. The team’s researchers, white hat hackers, and engineers collect information about possible attack paths to understand attacker motives, means, and methods in an effort to deliver the best protection possible.

About CyberMDX
CyberMDX is a pioneer in medical cybersecurity, with an IoMT solution that delivers visibility and threat prevention for medical devices and clinical assets. CyberMDX identifies, categorizes and protects connected medical devices — ensuring resiliency as well as patient safety and data privacy. With CyberMDX’s continuous endpoint discovery & mapping, comprehensive risk assessment, AI-powered containment & response, and operational analytics, risks are easily mitigated and assets optimized. For more information, please visit us at www.cybermdx.com

Jon Rabinowitz,
VP Marking CyberMDX
+1-201-970-5327

View original content:http://www.prnewswire.com/news-releases/cybermdx-research-team-discovers-medical-device-vulnerability-in-ge-anesthesia-and-respiratory-devices-300882135.html

SOURCE CyberMDX

Staff

Recent Posts

Lam Research Corporation Announces March Quarter Financial Conference Call

FREMONT, Calif., April 2, 2025 /PRNewswire/ -- Lam Research Corp. (NASDAQ: LRCX) today announced that…

50 minutes ago

Former Pfizer R&D Chief Mikael Dolsten Joins Formation Bio to Chair Drug Picking Committee and Co-Chair its Investment Advisory Committee

NEW YORK, April 2, 2025 /PRNewswire/ -- Formation Bio, an AI-driven pharmaceutical company revolutionizing drug development,…

51 minutes ago

Siemens acquires Dotmatics to extend AI-powered software portfolio to Life Sciences

Acquisition of Dotmatics, a leader in Life Sciences R&D software for $5.1 billionExpands Siemens' market-leading…

51 minutes ago

PerZeption Appoints CTO to Enhance Visual Function Assessments

BOSTON, April 2, 2025 /PRNewswire/ -- PerZeption Inc., a U.S. vision diagnostics startup dedicated to…

51 minutes ago

Dotmatics Signs Definitive Agreement to be Acquired by Siemens Advancing a New Era of AI-Driven Innovation in Life Sciences

Siemens AG will acquire Dotmatics from global software investor Insight Partners for $5.1 billionAcquisition accelerates…

51 minutes ago

AI-Native National Health Plan Angle Health Appoints Rhett Thurman as Chief Financial Officer

SAN FRANCISCO, April 2, 2025 /PRNewswire/ -- Angle Health, the AI-native, member- and patient-centric integrated…

51 minutes ago