Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

6/30/2020
06:15 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Ripple20 Threatens Increasingly Connected Medical Devices

A series of IoT vulnerabilities could put hospital networks, medical data, and patient safety at risk.

Earlier this month, JSOF security researchers disclosed the "Ripple20" vulnerabilities, a series of flaws affecting connected devices in the enterprise, industrial, and healthcare industries. Experts worry about the implications for connected medical devices, which could provide attackers with a gateway into a hospital network or enable them to affect patient care.

Ripple20 exists in a low-level TCP/IP software library built by software company Treck. Many IoT device manufacturers build the library directly into their devices or integrate it through embedded third-party components. As a result, organizations may not know they're exposed.

These vulnerabilities range in severity from small bugs with subtle effects to major flaws that could enable denial of service or information disclosure. Two of them could lead to remote code execution and allow a successful attacker to assume control over a target device. While an attacker would need to be on the network to exploit most of the Ripple20 vulnerabilities, this usually isn't difficult because many connected devices are often connected to the Internet by mistake.

Healthcare is "particularly susceptible" to Ripple20, report researchers with CyberMDX who aided JSOF in the investigation by helping to profile devices and identify exposure. Among the devices confirmed vulnerable are Baxter infusion pumps in the Sigma series, some B. Braun infusion pumps, a variety of Carestream products, some Schneider/APC UPS devices; some Digi network tools, some HP printers, and some Ricoh printers, all of which may put hospitals at risk.

"Inside hospitals we saw all kinds of affected devices," says Elad Luz, head of research with CyberMDX. Nonmedical devices such as network switches and printers, while not directly connected to patient health, are still critical to the workflow of providing medical care. 

"The Ripple20 vulnerabilities potential for manipulating the software of the device they run on," Luz explains. Most hospitals have "a fleet" of connected infusion pumps, for example, all of which have a user interface that lets care providers configure when functionality starts and stops. In a worst-case scenario, an attacker could interfere with the pump's capabilities and interrupt patient care; however, Luz points out that most attacks aren't meant to cause physical harm.

People who target medical devices, like most cybercriminals, are usually motivated by money. It's more likely they're planning to launch a ransomware attack or find medical records to sell on the black market. There, health data can fetch a higher price than credit card numbers because it can't be changed, Luz continues. Attackers may also seek to cause market manipulation by targeting a major healthcare organization with a cyberattack, he adds.

Vulnerabilities Plague Medical Devices
The security of connected medical devices is a growing concern as more of these products go online. Healthcare providers are driven by a need to treat a growing patient population, provide more telemedicine, and attempt to stem rising healthcare costs. Technology can help them do this; however, the integration of connected devices may also put patients and data at risk. 

"The reality we face is that medical devices can be in a hospital setting for 15 to 20 years, but new cybersecurity threats are emerging daily," said Rob Suárez, CISO at medical technology firm Becton, Dickinson and Company, in a panel held today on secured connected health. As cyberattacks continue to increase, many hospitals still lack a dedicated security expert, he said.

Medical devices are especially vulnerable compared with other IoT devices, PCs, and smartphones, Luz explains. Most of the connected medical products his team sees have a cybersecurity standard from 10 to 20 years ago, and they typically have different kinds of vulnerabilities. Many of these are design flaws, he adds. Medical devices may have poor means of authentication, connections for receiving telemetry, or managing and configuring the device.

The Ripple20 flaws are coding bugs and point to a problem in the software supply chain. In many cases, both inside and outside the healthcare field, companies receive a piece of software but don't know much about it. "If you don't know what the product is built out of, when those components end up having vulnerabilities, you don't know where to look," Suárez said.

What Hospitals Can Do
Treck released a new version of its software library (6.0.1.67) to address the Ripple20 flaws; however, the company can't update devices directly. The company offers vendors a development kit for when they package network stacks for their products. Until they use it to develop product firmware updates, the devices cannot be updated. 

"For hospitals, the challenging part is finding those affected devices," says Luz. If you're responsible for security at a hospital with 10,000 connected products of different models and vendors, locating the vulnerable ones will be difficult. 

Some medical devices require in-person updates, meaning the hospital would need a contract with the vendor to bring someone on-site to apply updates. This could prove tricky, he notes, as medical devices are critical and may not be available for updates at any time. Some vendors have a connection to the hospital and can automatically update affected machines remotely. Some may require a user to install an update. 

Related Content:

 
 
 
 
Learn from industry experts in a setting that is conducive to interaction and conversation about how to prepare for that "really bad day" in cybersecurity. Click for more information and to register for this On-Demand event. 

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
mosesbotbol
50%
50%
mosesbotbol,
User Rank: Apprentice
7/6/2020 | 3:17:35 PM
Re: "the company can't update devices directly"
How they are updated should be a consideration before onboarding any IOT device.
JerryReichert
50%
50%
JerryReichert,
User Rank: Apprentice
7/6/2020 | 3:02:29 AM
Re: "the company can't update devices directly"
??
Qualitybacklinks
50%
50%
Qualitybacklinks,
User Rank: Apprentice
7/4/2020 | 7:23:43 AM
Re: Affected devices
yes, i hope so
FlynneTrobe
50%
50%
FlynneTrobe,
User Rank: Apprentice
6/30/2020 | 10:59:43 PM
Re: Affected devices
yes, i hope so
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
6/30/2020 | 10:47:40 PM
Re: Affected devices
With the sheer number of devices you would need them to check into a hub locally and then check in remotely. Either way thats going to be heavy on network throughput. 
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
6/30/2020 | 10:46:27 PM
Re: "the company can't update devices directly"
Most definitely and I think they should continue to prioritize health objectives ahead of security when medical devices can save lives. But there still needs to be security in mind because if not then those same devices could be used to cause harm.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/30/2020 | 8:14:14 PM
Updates and repairs
This could prove tricky, he notes, as medical devices are critical and may not be available for updates at any time. Yes. All these devices should get updates remotely. Maybe having spares so no need to wait for the repairs.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/30/2020 | 8:11:52 PM
Affected devices
For hospitals, the challenging part is finding those affected devices," says Luz. If you're responsible for security at a hospital with 10,000 connected products of different models and vendors, locating the vulnerable ones will be difficult. This would be almost impossible unless devices somehow scan able remotely.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/30/2020 | 8:10:04 PM
Re: "the company can't update devices directly"
Unfortunately, in many cases such as this I noticed that the HCP is slow to react historically. I agree. Also I do not believe neither hospitals nor medical provided accept dramatic change in their processes so that makes it harder.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/30/2020 | 8:08:25 PM
Re: "the company can't update devices directly"
This puts the accountability back on the healthcare providers that are providing these devices. I agree. Most these devices were build convenience in mind so security will certainly suffer.
Page 1 / 2   >   >>
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/21/2020
Cybersecurity Bounces Back, but Talent Still Absent
Simone Petrella, Chief Executive Officer, CyberVista,  9/16/2020
Meet the Computer Scientist Who Helped Push for Paper Ballots
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/16/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Latest Comment: Exactly
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-4643
PUBLISHED: 2020-09-21
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information. IBM X-Force ID: 185590.
CVE-2020-4590
PUBLISHED: 2020-09-21
IBM WebSphere Application Server Liberty 17.0.0.3 through 20.0.0.9 running oauth-2.0 or openidConnectServer-1.0 server features is vulnerable to a denial of service attack conducted by an authenticated client. IBM X-Force ID: 184650.
CVE-2020-4731
PUBLISHED: 2020-09-21
IBM Aspera Web Application 1.9.14 PL1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188055.
CVE-2020-4315
PUBLISHED: 2020-09-21
IBM Business Automation Content Analyzer on Cloud 1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the i...
CVE-2020-4579
PUBLISHED: 2020-09-21
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted HTTP/2 request with invalid characters. IBM X-Force ID: 184438.