Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Hackers Could Harm Diabetics via Insulin Pump Attacks

OneTouch Ping insulin pumps manufactured by Johnson & Johnson-owned Animas are plagued by several vulnerabilities that can be exploited by remote hackers to compromise devices and potentially harm the diabetic patients who use them. While the security holes are serious, the risk is considered relatively low and the vendor does not plan on releasing a firmware update.

OneTouch Ping insulin pumps manufactured by Johnson & Johnson-owned Animas are plagued by several vulnerabilities that can be exploited by remote hackers to compromise devices and potentially harm the diabetic patients who use them. While the security holes are serious, the risk is considered relatively low and the vendor does not plan on releasing a firmware update.

Rapid7 researcher Jay Radcliffe, who has been a Type I diabetic for 17 years, analyzed Animas’ OneTouch Ping insulin pumps. The product has two main components: the actual insulin pump and a remote that controls the pump’s functions from up to 10 feet away.

The four major vulnerabilities found by Radcliffe in the OneTouch Ping product have been detailed in a Rapid7 blog post and an advisory published by the Department of Homeland Security’s CERT Coordination Center.

The researcher discovered that the remote and the pump communicate over an unencrypted channel (CVE-2016-5084), allowing a man-in-the-middle (MitM) attacker to intercept patient treatment and device data. The vendor pointed out that while some data is exposed, it does not include any personally identifiable information.

Another vulnerability identified by Radcliffe is related to the setup process where the pump is paired with the remote – pairing is needed to prevent the pump from accidentally accepting commands from other remotes. The key used by the devices when they exchange information is based on serial numbers and some header information and it’s transmitted without any form of encryption.

OneTouch Ping insulin pump and remote

This weak pairing (CVE-2016-5085) allows an attacker to spoof the remote and issue commands to arbitrarily dispense insulin, which could lead to the patient having a hypoglycemic reaction.

The researcher also noticed that OneTouch Ping pumps lack protection against replay (CVE-2016-5086) and spoofing (CVE-2016-5686) attacks. These vulnerabilities can be exploited to capture packets and replay them at a later time, or send spoofed packets with arbitrary commands to the pump. In both cases, the attacker can instruct the device to dispense insulin and potentially harm the user.

The OneTouch Ping pump and its remote are not connected to the Internet so these attacks cannot be carried out over very long distances. However, special radio transmission equipment could allow attacks to be conducted from hundreds of feet and possibly even up to one mile, researchers warned.

Advertisement. Scroll to continue reading.

While these are serious vulnerabilities, Radcliffe said the risk is relatively low and the goal of the research is to raise awareness, allow users to make informed decisions, and get manufacturers to focus more on security when designing their products.

“Removing an insulin pump from a diabetic over this risk is similar to never taking an airplane because it might crash,” the expert noted.

Johnson & Johnson, which notified patients and healthcare professionals of Rapid7’s findings via physical mail, said it does not plan on releasing a firmware update to address the vulnerabilities. However, the company has provided instructions on how attacks can be mitigated using various features available in the OneTouch Ping product.

Rapid7’s approach contrasts with the path taken in August by medical device security firm MedSec, which decided to disclose vulnerabilities found in St. Jude Medical products without notifying the vendor. MedSec decided to team up with an investment research company that used the findings as part of an investment strategy, which led to St. Jude filing a lawsuit.

Related: FDA Issues Alert Over Vulnerable Hospira Drug Pumps

Related: Serious Security Flaws Found in Hospira LifeCare Drug Pumps

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

IoT Security

A vulnerability affecting Dahua cameras and video recorders can be exploited by threat actors to modify a device’s system time.