GE Aespire & Aestive Improper Authentication Vulnerability
GE Healthcare has released details of an improper authentication vulnerability affecting their Aespire and Aestive anaesthesia delivery products. A remote, unauthenticated attacker could exploit this vulnerability to alter anaesthesia delivery parameters or silence device alarms.
Summary
GE Healthcare has released details of an improper authentication vulnerability affecting their Aespire and Aestive anaesthesia delivery products. A remote, unauthenticated attacker could exploit this vulnerability to alter anaesthesia delivery parameters or silence device alarms.
Threat details
The vulnerability is a result of the terminal server implementations used to connect Aespire and Aestive serial ports to TCP/IP networks. Certain configurations can expose the terminal server, which by default do not require authentication. An attacker with knowledge of the configuration and access to the same network segment could gain access to any affected Aespire and Aestive devices on the same segment.
For further information:
- CVE-2019-10966 (CVSS v3 5.3 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
- ICS Medical Advisory ICSMA-19-190-01
Remediation steps
| Type | Step |
|---|---|
|
GE Healthcare have recommended that affected organisations connect Aespire and Aestiva devices using secure terminal servers. These servers should provide robust security features, including:
Proper network segmentation and virtual private networks should also be used to ensure affected devices and their terminal servers are suitably separated from other network activity. Organisations are encouraged to review GE Healthcare's dedicated security page for further security information and guidance. |
Last edited: 14 February 2020 2:52 pm