Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Vulnerabilities in Medical Devices
News & Analysis

Vulnerabilities in Medical Devices

ISBuzz TeamBy ISBuzz TeamFebruary 25, 2016Updated:July 3, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Vulnerabilities in Medical Devices
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

According to a new report, “the healthcare sector is a good 10 to 15 years behind the retail sector when it comes to security.” “We can’t accept what we have now. If we assume a loss of life scenario, the consequence of failure is too high.” Said Scott Erven, a medical device security advocate who spoke at last week’s Security Analyst Summit.

Following this news, security experts from AlienVault and Lieberman Software discuss whether there genuinely is a possibility of death due to vulnerabilities in medical devices, as well as what should be done to protect them.

[su_note note_color=”#ffffcc” text_color=”#00000″]Javvad Malik, Security Advocate at AlienVault:

  • Do you agree that these vulnerabilities can actually lead to death?

“Whenever you’re dealing with medicine at large, the consequences can be huge. Considering even an overdose of a non-prescription drug such as Paracetamol can lead to death. The biggest challenge comes from where medical devices are remotely accessible.

You can break these devices down into two parts:

  1. Those devices which administer treatment or medication of some sort.
  2. Those devices which doctors rely on to make decisions.

For the first type, causing a system to increase or decrease medication can have a direct impact on someone’s life.

While the second type of device may not directly impact someone, it can cause a doctor to make an incorrect diagnosis. In both scenarios there exists the potential to impact life – albeit in different ways.

There’s been a ton of independent research conducted from a variety of different professionals demonstrating the vulnerabilities that exist. A lot of the flaws tie back to the wider IoT issues – old systems, getting updated with internet connectivity for the sake of convenience with little or no thought given to security. Just because you can automate a device or make it remotely accessible, doesn’t mean that you should.”

  • What needs to be done?

“Security is often a tough sell. The vulnerabilities exist somewhat due to budget constraints and others due to technological constraints. For example, some medical devices are said to have weak or unchangeable passwords. Or doesn’t include encryption or authentication controls.

Hospitals themselves need to evaluate their internal networks and how systems are connected and authenticated. This will vary in different hospitals, but creating secure trusted zones for medical devices, continually monitoring for unusual activity and other best practises are a must.”

“Secure development and system hardening should be implemented when a device is first manufactured and shipped.

But perhaps more importantly, the vendors should keep researching the latest threats as they develop and issue patches and fixes where appropriate. If these are not possible, they should at the very least be issuing advisories with recommendations of mitigating controls.

Building in manual override or recovery options to continue using machinery even if offline.

Having integrity and other assurance processes and technologies in place to ensure systems are operating as designed.”[/su_note]

[su_note note_color=”#ffffcc” text_color=”#00000″]Jonathan Sander, VP of Product Strategy at Lieberman Software:

  • Do you agree that these vulnerabilities can actually lead to death?

“The security vulnerabilities found in medical devices could lead to someone’s death in the same way that walking on the sidewalk could lead to your death if a driver decided to mount the curb and aim for you. Most breaches and exploits happen for some reason. Bad guys infect your machine with Cryptowall in order to blackmail you, but if they kill you with a faulty medical device who would pay them. Of course, maybe someone is paying them to kill you or they are just a psychopath entertaining themselves. These are hardly likely, but not impossible.

One example of the type of flaw found in these devices is hard coded, default passwords. If you’ve ever had to set up a device like a wireless router in your home and had to use a password that was written in the device’s instructions, then you’ve encountered this. A good manual will tell you to change that default password immediately, but many do not instruct that and most people don’t listen when they do. Medical devices also often come with a password that ought to be changed but isn’t. That means any bad guy with the instructions for the device can do real harm quite easily if they wish.”

  • What needs to be done?

“No effort is without cost. Mitigating the security flaws would cost money and time many medical facilities don’t think they have. The real question is if the risk is more expensive than the solution.”[/su_note]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}