Mobile & Wireless

Decommissioned Medical Infusion Pumps Expose Wi-Fi Configuration Data

Medical infusion pumps available via secondary market sources contain Wi-Fi configuration settings from the original organization.

Medical infusion pumps available via secondary market sources contain Wi-Fi configuration settings from the original organization.

Most medical infusion pumps sold via secondary market sources still contain Wi-Fi configuration settings from the original organization that deployed them, cybersecurity firm Rapid7 has discovered.

An analysis of 13 infusion pump devices revealed that wireless authentication data had not been purged from them prior to de-acquisition, exposing this data to third-parties purchasing these devices from secondary market sources, such as eBay.

Rapid7 analyzed three different infusion pump models, namely the Alaris PC 8015, the Baxter Sigma Spectrum model 35700BAX2 and associated Wireless Battery Module (WBM), and the Hospira Abbott PLUM A+ with MedNet.

No longer manufactured, these devices are still in use within numerous medical organizations worldwide, representing a potential security risk if data on them is not properly purged prior to decommissioning.

For their investigation, Rapid7’s security researchers attempted the extraction of sensitive data from devices’ compact flash cards, by observing serial communication, and by removing the flash memory chips from the main circuit boards.

On the Alaris 8015, the researchers discovered hostnames with domain information, AES keys for encryption, service set identifiers (SSIDs), the clear text Wi-Fi Pre Shared Keys (PSK) passphrase, credentials for Microsoft Active Directory authentication, and Wi-Fi configuration settings.

While there is no documentation regarding the data purge process for the Alaris 8015 decommissioning found online, Alaris did publish security service bulletins that are available for organizations having support contracts with Becton, Dickinson and Company (BD).

Rapid7 also analyzed multiple Baxter Sigma Spectrum 35700BAX2 devices and associated Wireless Battery Module (WBM) and discovered that they too stored Wi-Fi configuration data, including the Wi-Fi Protected Access (WPA) passphrase converted to a 64-character hex key (PSK).

Advertisement. Scroll to continue reading.

Baxter, the cybersecurity firm notes, does provide documentation detailing the steps that should be taken to reset wireless configurations and remove any other information from both the device and the WBM.

The Hospira Abbott PLUM A+ with MedNet too was found to store Wi-Fi configuration information, but, according to Rapid7, “no single procedure could be located that detailed the needed steps for removing all critical data such as PHI, and Wi-Fi configuration data in preparation of decommissioning.”

The equipment used for extracting data from these devices, Rapid7 notes, is relatively cheap, with an estimated price range of $250-$1,500, which makes it affordable for a wide range of threat actors.

“The discovery of this data on de-acquisitioned medical devices being sold on the secondary market points out a serious systemic issue. The only way to effectively resolve this issue is for organizations that leverage medical technologies to build out policies and processes for how to properly handle the acquisition and de-acquisition of medical technology,” Rapid7 notes.

Related: Rapid7 Flags Multiple Flaws in Sigma Spectrum Infusion Pumps

Related: Infusion Pumps Impacted by Years-Old Critical Vulnerabilities: Report

Related: FBI Warns of Unpatched and Outdated Medical Device Risks

Related Content

Mobile & Wireless

A couple of Wi-Fi authentication bypass vulnerabilities found in open source software can expose enterprise and home networks to attacks.

Malware & Threats

Mysterious Whiffy Recon malware scans for nearby Wi-Fi access points to obtain the location of the infected device.

Mobile & Wireless

Ford says a critical vulnerability in the TI Wi-Fi driver of the SYNC 3 infotainment system on certain vehicle models does not pose a...

Cybercrime

A cyberattack has disrupted hospital computer systems in several states, forcing some emergency rooms to close and ambulances to be diverted.

Mobile & Wireless

Canon says more than 200 inkjet printer models fail to properly erase Wi-Fi configuration settings.

Cybercrime

Canadian medical software provider CardioComm has taken systems offline to contain a cyberattack.

IoT Security

The FDA is asking medical device manufacturers to provide cybersecurity-related information when submitting an application for a new product.

Mobile & Wireless

A group of academic researchers devised an attack that can intercept Wi-Fi traffic at the MAC layer, bypassing client isolation.

Copyright © 2024 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version