Hacking Drug Infusion Pumps, never so easy

Certain versions of common drug infusion pumps are affected by numerous remotely exploitable vulnerabilities that could not open the doors to hackers.

We discussed several times about the opportunity to hack medical devices and the needs of security by design for these objects. In 2012 the US Government Accountability Office (GAO) published a report that highlighted the necessity to secure medical devices such as implantable cardioverter defibrillators or insulin pumps. The recommendation was directed to the Food and Drug Administration (FDA) and invited it to approach the problem seriously considering the risks of

News of the day is that a specific versions of Hospira’s Lifecare PCA3 Drug Infusion pumps are affected by a number of vulnerabilities that could be exploited by attackers remotely to completely take over the devices.

The researcher that discovered the vulnerabilities was disconcerted by the possible implication for the security of the patient.

In October 2014, the US  ICS-CERT was assessing several products, including an infusion pump from Hospira Inc and implantable heart devices commercialized by Medtronic Inc and St Jude Medical Inc. Rumors referred that in one case was involved an alleged vulnerability in a type of infusion pump discovered by the security expert Billy Rios who declined to provide the name of the manufacturer.

“Two people familiar with his research said the manufacturer was Hospira.” states the Reuters in a blog post.

The vulnerability discovered by the researcher recently could be exploited to block the device, change the drug library they’re affiliated with, run commands and update its software.

“I would personally be very concerned if this device was being attached to me,” wrote Jeremy Richards, a Software Security Engineer at the SAINT Corporation who discovered the vulnerabilities. “It is not only susceptible to attack, it is so poorly programmed it can be rendered a useless brick with a single typo.”

The expert discovered serious security issues in the pumps, the medical devices have the factory IP address 192.168.0.100, that could be used by an attacker to extract wireless encryption keys, which are stored in plain text on the medical device. If an attacker had physical access to the device, they could not only gain access to the keys and compromise the pump, but by extension, any drug pumps in the hospital connected to the same WiFi.

“The WPA keys for the ‘super secure’ hospital wireless network sit on these machines unencrypted and plain text.  They are stored in ‘/ram/mnt/jffs2/config’ and can be accessed over Telnet and FTP.  Since these pumps are designed to stay attached to patients local access needs to be considered.  These devices are configured to exist on a medical device network.  This also needs to be considered by hospitals selling their old equipment.” Richards added.

The problems are not limited to the single pump, if an attacker had physical access to the device, he can take over the pump and any other drug pumps in the hospital connected to its WiFi.

Richards explained that a local physical attack could be easily carried out is a few seconds through the ethernet port by using a device like the Raspberry Pi. “This is a game-over vulnerability that allows an attacker with physical access to the device complete control over their own device,” Richards wrote.

“This is a game-over vulnerability that allows an attacker with physical access to the device complete control over their own device,” Richards wrote.

One of the vulnerabilities was coded as CVE-2015-3459, it is related to the lack of authentication for Telnet sessions for pumps running SW version 412. An attacker exploiting the flaw can remotely gain root privileges via TCP port 23.

“Hospira Lifecare PCA infusion pump running “SW ver 412” does not require authentication for Telnet sessions, which allows remote attackers to gain root privileges via TCP port 23.” states the description proposed for the flaw in the National Vulnerability Database.

There are many other security issues related to the medical devices, ill-intentioned could retrieve information related to hard coded accounts were found stored on the device. Despite this information are hashed it is quite easy to crack them by using bruteforce attacks,

.htpasswd file in /ram/mnt/jffs2/config
Admin:e6VERxIM2M1aY
hospira:Ok6EEl22j2/6w

Attackers can also glean information related to hard coded local accounts and on top of that, a server, AppWeb, that runs in tandem with the device suffers from its own separate vulnerabilities as well.

The issue is complicated by the fact that even if there was authentication present on the Telnet port, it wouldn’t help, since there are several web services, exposed CGIs “linkparams” and “xmmucgi,” that don’t require authentication which an attacker could exploit to “change the drug library, update software and run commands.”

Richards also highlighed the presence of a vulnerable web server, AppWeb server running v1.0.2, and many other web services exposed CGIs “linkparams” and “xmmucgi,” that don’t require authentication and that could be easily hacked.

Richards reported the issued to manufacturer Hospira, but it apparently has no plans to fix the issue.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs –  medical pumps, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Silent Ransom Group targeting law firms, the FBI warns

FBI warns Silent Ransom Group has targeted U.S. law firms for 2 years using callback…

46 minutes ago

Leader of Qakbot cybercrime network indicted in U.S. crackdown

The U.S. indicted Russian Rustam Gallyamov for leading the Qakbot botnet, which infected 700K+ devices…

6 hours ago

Operation RapTor led to the arrest of 270 dark web vendors and buyers

Law enforcement operation codenamed 'Operation RapTor' led to the arrest of 270 dark web vendors…

1 day ago

Chinese threat actors exploited Trimble Cityworks flaw to breach U.S. local government networks

A Chinese threat actor, tracked as UAT-6382, exploited a patched Trimble Cityworks flaw to deploy…

1 day ago

U.S. CISA adds a Samsung MagicINFO 9 Server flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Samsung MagicINFO 9 Server vulnerability to its…

2 days ago

New Signal update stops Windows from capturing user chats

Signal implements new screen security on Windows 11, blocking screenshots by default to protect user…

2 days ago