City
Epaper

Medtronic's heart device data management system vulnerable to hacking

By IANS | Published: July 02, 2023 2:06 PM

New York, July 2 American medical device company Medtronic said it has identified a vulnerability in its heart ...

Open in App

New York, July 2 American medical device company Medtronic said it has identified a vulnerability in its heart device data management system, which if exploited can lead to data being deleted, stolen, or modified.

Medtronic's Paceart Optima is a software application that runs on a healthcare delivery organisation's Windows server. The application collects, stores, and retrieves cardiac device data from programmers and remote monitoring systems from all major cardiac device manufacturers to aid in standard workflows.

The company said during routine monitoring it identified a vulnerability in the applications' optional messaging feature, that is "not configured by default, and cannot be exploited unless enabled", the company said in a security bulletin.

If a healthcare delivery organisation has enabled the optional service, "an unauthorised user could exploit this vulnerability to perform Remote Code Execution (RCE) and/or Denial of Service (DoS) attacks by sending specially crafted messages to the Paceart Optima system," the company said.

While a RCE could result in the Paceart Optima system's cardiac device data being deleted, stolen, or modified, or the Paceart Optima system being used for further network penetration, a DoS attack could cause the Paceart Optima system to become slow or unresponsive.

Besides, the vulnerability was seen specifically in the Paceart messaging service’s implementation of the Microsoft message queuing protocol.

The messaging service enables healthcare delivery organisations to send fax, email, and pager messages within the Paceart Optima system.

Medtronic said it has not so far "observed any cyberattacks, unauthorised access to or loss of patient data, or harm to patients related to this issue". But to eliminate such a possibility, companies can install a new update of the data management system.

The vulnerability is present in Paceart Optima system versions 1.11 and earlier.

The company thus asked all healthcare providers using versions 1.11 and earlier of the system to contact the company to schedule an update to the issue-mitigating version 1.12 software.

Meanwhile, Medtronic also provided immediate, temporary steps to prevent the exploitation of this vulnerability such as how to disable the messaging service and the message queuing feature.

However, it said, even after those steps are taken, "the vulnerable code will still be present in the application, but will no longer be exploitable."

"For a complete mitigation on the application server, update the Paceart Optima system to version 1.12. This update removes the Paceart Messaging Service function and fully remediates the vulnerability on the Application Server," the company said.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Tags: microsoftMedtronicMicrosoft TheaterMicrosoft IndiaMicrosoft HololensMicrosoft TeamsMicrosoft OfficeMicrosoft ResearchMicrosoft AzureMicrosoft Azure Cloud
Open in App

Related Stories

NationalUnion Minister Ashwini Vaishnaw Urges Tech Giants Meta, Google, Amazon, and Microsoft to Take Responsibility Against Misinformation

Social Viral‘India, You Can Find Innovation Everywhere’: Bill Gates Shares Video With Nagpur Tea Seller ‘Dolly Chaiwalla’

TechnologyMicrosoft Cyber Attack: No Customer Data or Source Code Was Compromise, Says Company

BusinessEx-Microsoft CEO Steve Ballmer to receive 8300 crore from company for doing nothing

TechnologyMicrosoft joins OpenAI’s board, Sam Altman returns as CEO

Technology Realted Stories

TechnologySamsung Galaxy A54, A34 now receiving One UI 6.1 update

TechnologyOpenAI launches new ‘GPT-4o’ AI model for all ChatGPT users

TechnologyTCS announces to create global AI centre of excellence in France

TechnologySmartphone sales in US expected to grow only 3 per cent by 2028: Report

TechnologySouth Korea inks consumer safety pacts with China's AliExpress, Temu