Skip to main content

Hamilton-T1 Ventilator Vulnerabilities

Three vulnerabilities in Hamilton Medical's T1 ventilators have been disclosed. A user with physical access could exploit these to steal data or disable affected systems.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Three vulnerabilities in Hamilton Medical's T1 ventilators have been disclosed. A user with physical access could exploit these to steal data or disable affected systems.


Affected platforms

The following platforms are known to be affected:

Hamilton Medical T1 Versions: 2.2.3 and earlier


Threat details

Introduction

Hamilton Medical has released details of three vulnerabilities in their T1 ventilators. They claim that a physical attacker could exploit some or all of these vulnerabilities to extract sensitive information or cause a denial-of-service condition.


Vulnerability details

All three vulnerabilities appear to be the result of improper authentication checks when allowing physical users access to vulnerable T1 systems:

  • CVE-2020-27278 - T1 systems use hard-coded credentials, allowing a physical user to obtain administrative privileges.
  • CVE-2020-27282 - T1 systems improperly validate XML config files, allowing physical users to upload specially crafted config files and disabling the system.
  • CVE-2020-27290 - T1 systems do not sufficiently check config log checksums, allowing a physical user to pass tampered config files to the system.

Remediation advice

Hamilton Medical has confirmed that all three vulnerabilities have been addressed in all T1 firmware versions later than 2.23. Affected organisations are encouraged to contact their relevant suppliers and apply any necessary updates



Last edited: 3 March 2021 4:02 pm