Skip to main content

GE Aespire & Aestive Improper Authentication Vulnerability

GE Healthcare has released details of an improper authentication vulnerability affecting their Aespire and Aestive anaesthesia delivery products. A remote, unauthenticated attacker could exploit this vulnerability to alter anaesthesia delivery parameters or silence device alarms.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

GE Healthcare has released details of an improper authentication vulnerability affecting their Aespire and Aestive anaesthesia delivery products. A remote, unauthenticated attacker could exploit this vulnerability to alter anaesthesia delivery parameters or silence device alarms.


Threat details

The vulnerability is a result of the terminal server implementations used to connect Aespire and Aestive serial ports to TCP/IP networks. Certain configurations can expose the terminal server, which by default do not require authentication. An attacker with knowledge of the configuration and access to the same network segment could gain access to any affected Aespire and Aestive devices on the same segment.

For further information:


Remediation steps

Type Step

GE Healthcare have recommended that affected organisations connect Aespire and Aestiva devices using secure terminal servers. These servers should provide robust security features, including:

  • suitable user authentication
  • proper network controls
  • strong encryption
  • adequate logging and auditing capabilities
  • secure device configuration and management options

Proper network segmentation and virtual private networks should also be used to ensure affected devices and their terminal servers are suitably separated from other network activity.

Organisations are encouraged to review GE Healthcare's dedicated security page for further security information and guidance.


Last edited: 14 February 2020 2:52 pm