Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

6/30/2020
06:15 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Ripple20 Threatens Increasingly Connected Medical Devices

A series of IoT vulnerabilities could put hospital networks, medical data, and patient safety at risk.

Earlier this month, JSOF security researchers disclosed the "Ripple20" vulnerabilities, a series of flaws affecting connected devices in the enterprise, industrial, and healthcare industries. Experts worry about the implications for connected medical devices, which could provide attackers with a gateway into a hospital network or enable them to affect patient care.

Ripple20 exists in a low-level TCP/IP software library built by software company Treck. Many IoT device manufacturers build the library directly into their devices or integrate it through embedded third-party components. As a result, organizations may not know they're exposed.

These vulnerabilities range in severity from small bugs with subtle effects to major flaws that could enable denial of service or information disclosure. Two of them could lead to remote code execution and allow a successful attacker to assume control over a target device. While an attacker would need to be on the network to exploit most of the Ripple20 vulnerabilities, this usually isn't difficult because many connected devices are often connected to the Internet by mistake.

Healthcare is "particularly susceptible" to Ripple20, report researchers with CyberMDX who aided JSOF in the investigation by helping to profile devices and identify exposure. Among the devices confirmed vulnerable are Baxter infusion pumps in the Sigma series, some B. Braun infusion pumps, a variety of Carestream products, some Schneider/APC UPS devices; some Digi network tools, some HP printers, and some Ricoh printers, all of which may put hospitals at risk.

"Inside hospitals we saw all kinds of affected devices," says Elad Luz, head of research with CyberMDX. Nonmedical devices such as network switches and printers, while not directly connected to patient health, are still critical to the workflow of providing medical care. 

"The Ripple20 vulnerabilities potential for manipulating the software of the device they run on," Luz explains. Most hospitals have "a fleet" of connected infusion pumps, for example, all of which have a user interface that lets care providers configure when functionality starts and stops. In a worst-case scenario, an attacker could interfere with the pump's capabilities and interrupt patient care; however, Luz points out that most attacks aren't meant to cause physical harm.

People who target medical devices, like most cybercriminals, are usually motivated by money. It's more likely they're planning to launch a ransomware attack or find medical records to sell on the black market. There, health data can fetch a higher price than credit card numbers because it can't be changed, Luz continues. Attackers may also seek to cause market manipulation by targeting a major healthcare organization with a cyberattack, he adds.

Vulnerabilities Plague Medical Devices
The security of connected medical devices is a growing concern as more of these products go online. Healthcare providers are driven by a need to treat a growing patient population, provide more telemedicine, and attempt to stem rising healthcare costs. Technology can help them do this; however, the integration of connected devices may also put patients and data at risk. 

"The reality we face is that medical devices can be in a hospital setting for 15 to 20 years, but new cybersecurity threats are emerging daily," said Rob Suárez, CISO at medical technology firm Becton, Dickinson and Company, in a panel held today on secured connected health. As cyberattacks continue to increase, many hospitals still lack a dedicated security expert, he said.

Medical devices are especially vulnerable compared with other IoT devices, PCs, and smartphones, Luz explains. Most of the connected medical products his team sees have a cybersecurity standard from 10 to 20 years ago, and they typically have different kinds of vulnerabilities. Many of these are design flaws, he adds. Medical devices may have poor means of authentication, connections for receiving telemetry, or managing and configuring the device.

The Ripple20 flaws are coding bugs and point to a problem in the software supply chain. In many cases, both inside and outside the healthcare field, companies receive a piece of software but don't know much about it. "If you don't know what the product is built out of, when those components end up having vulnerabilities, you don't know where to look," Suárez said.

What Hospitals Can Do
Treck released a new version of its software library (6.0.1.67) to address the Ripple20 flaws; however, the company can't update devices directly. The company offers vendors a development kit for when they package network stacks for their products. Until they use it to develop product firmware updates, the devices cannot be updated. 

"For hospitals, the challenging part is finding those affected devices," says Luz. If you're responsible for security at a hospital with 10,000 connected products of different models and vendors, locating the vulnerable ones will be difficult. 

Some medical devices require in-person updates, meaning the hospital would need a contract with the vendor to bring someone on-site to apply updates. This could prove tricky, he notes, as medical devices are critical and may not be available for updates at any time. Some vendors have a connection to the hospital and can automatically update affected machines remotely. Some may require a user to install an update. 

Related Content:

 
 
 
 
Learn from industry experts in a setting that is conducive to interaction and conversation about how to prepare for that "really bad day" in cybersecurity. Click for more information and to register for this On-Demand event. 

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
Page 1 / 2   >   >>
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
6/30/2020 | 7:30:03 PM
"the company can't update devices directly"
This puts the accountability back on the healthcare providers that are providing these devices. Unfortunately, in many cases such as this I noticed that the HCP is slow to react historically.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/30/2020 | 8:06:14 PM
Connected devices
Experts worry about the implications for connected medical devices, which could provide attackers with a gateway into a hospital network or enable them to affect patient care. Obviously connected devices in an hospital settings will have the same risk level as all other places. It may be more fatal unfortunately.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/30/2020 | 8:08:25 PM
Re: "the company can't update devices directly"
This puts the accountability back on the healthcare providers that are providing these devices. I agree. Most these devices were build convenience in mind so security will certainly suffer.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/30/2020 | 8:10:04 PM
Re: "the company can't update devices directly"
Unfortunately, in many cases such as this I noticed that the HCP is slow to react historically. I agree. Also I do not believe neither hospitals nor medical provided accept dramatic change in their processes so that makes it harder.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/30/2020 | 8:11:52 PM
Affected devices
For hospitals, the challenging part is finding those affected devices," says Luz. If you're responsible for security at a hospital with 10,000 connected products of different models and vendors, locating the vulnerable ones will be difficult. This would be almost impossible unless devices somehow scan able remotely.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/30/2020 | 8:14:14 PM
Updates and repairs
This could prove tricky, he notes, as medical devices are critical and may not be available for updates at any time. Yes. All these devices should get updates remotely. Maybe having spares so no need to wait for the repairs.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
6/30/2020 | 10:46:27 PM
Re: "the company can't update devices directly"
Most definitely and I think they should continue to prioritize health objectives ahead of security when medical devices can save lives. But there still needs to be security in mind because if not then those same devices could be used to cause harm.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
6/30/2020 | 10:47:40 PM
Re: Affected devices
With the sheer number of devices you would need them to check into a hub locally and then check in remotely. Either way thats going to be heavy on network throughput. 
FlynneTrobe
50%
50%
FlynneTrobe,
User Rank: Apprentice
6/30/2020 | 10:59:43 PM
Re: Affected devices
yes, i hope so
Qualitybacklinks
50%
50%
Qualitybacklinks,
User Rank: Apprentice
7/4/2020 | 7:23:43 AM
Re: Affected devices
yes, i hope so
Page 1 / 2   >   >>
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/17/2020
Cybersecurity Bounces Back, but Talent Still Absent
Simone Petrella, Chief Executive Officer, CyberVista,  9/16/2020
Meet the Computer Scientist Who Helped Push for Paper Ballots
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/16/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-25789
PUBLISHED: 2020-09-19
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript inside an SVG document.
CVE-2020-25790
PUBLISHED: 2020-09-19
** DISPUTED ** Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the vendor disputes the significance of this report because "admins are considered trustworthy"; however, the behavior "contradicts our secu...
CVE-2020-25791
PUBLISHED: 2020-09-19
An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, the array size is not checked when constructed with unit().
CVE-2020-25792
PUBLISHED: 2020-09-19
An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, the array size is not checked when constructed with pair().
CVE-2020-25793
PUBLISHED: 2020-09-19
An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, the array size is not checked when constructed with From<InlineArray<A, T>>.