{"id":7352,"date":"2022-07-06T07:31:01","date_gmt":"2022-07-06T14:31:01","guid":{"rendered":"https:\/\/webdev.securin.xyz\/?p=7352"},"modified":"2023-04-05T12:32:29","modified_gmt":"2023-04-05T19:32:29","slug":"43-weaponized-cves-in-healthcare-products-threaten-patient-care","status":"publish","type":"post","link":"https:\/\/webdev.securin.xyz\/articles\/43-weaponized-cves-in-healthcare-products-threaten-patient-care\/","title":{"rendered":"43 Weaponized CVEs in Healthcare Products Threaten Patient Care"},"content":{"rendered":"

In the last few years, we have seen rising incidents targeting the Healthcare sector. From network outages to hampered monitoring, to hacked pneumatic pumps and IV infusion tubes administering fatal doses to patients, a cyber attack on the healthcare industry can have huge repercussions.<\/p>\n

 <\/p>\n

CSW researchers investigated 56 vendors and 846 products overall, and identified 624 vulnerabilities across them and here are our key findings.<\/strong><\/p>\n

Key Findings<\/h2>\n
    \n
  1. \n

    CSW researchers identified 624 vulnerabilities overall that could be exploited by attackers to target a healthcare facility. Of these 43 are weaponized, 12 of them are trending in the wild, four are being exploited by Advanced Persistent Threat Groups and two are associated with ransomware.<\/p>\n<\/li>\n

  2. \n

    8 CVEs are categorized as RCE\/PE exploits which makes them dangerous and attractive to hackers.<\/p>\n<\/li>\n

  3. \n

    We have identified six vulnerabilities that exist in healthcare products and medical devices that could cause patient fatality and disability.<\/p>\n<\/li>\n

  4. \n

    We investigated 56 vendors and 846 products and found the highest number of vulnerabilities (64%) in software applications that are used in the healthcare industry.<\/p>\n<\/li>\n

  5. \n

    29% of vulnerabilities identified in our study have a high chance of exploitation by hackers.<\/p>\n<\/li>\n<\/ol>\n

    Our researchers identified that it is not just medical devices that pose a danger to the health care sector. Indirectly used products like software applications, firmware, hardware, and operating systems also gave rise to vulnerabilities, compromising which could give attackers control over healthcare equipment.<\/p>\n

    In this blog, we dive deep into CSW\u2019s research into healthcare products, and spotlight the danger that this critical industry segment faces day on day.\u00a0<\/strong><\/p>\n


    \nCSW\u2019s Healthcare and Medical Device\u00a0Products Investigation<\/h2>\n

    CSW researchers identified 624 vulnerabilities overall that could be exploited by attackers.<\/p>\n

    Healthcare Vulnerability Overview<\/em><\/span><\/p>\n

    \"\"<\/em><\/span><\/p>\n

    The Dangerous Targets: <\/strong>43 weaponized vulnerabilities exist in products used day in and day out for delivering patient care. These vulnerabilities either have publicly available exploits or are actively targeted by threat actors, making them a danger to healthcare networks, if left unpatched.<\/p>\n

    <\/p>\n

    High Impact Targets:<\/strong> With over 50% of the vulnerabilities belonging to the high and critical severity categories, attackers have 351 different ways to enter into hospital or healthcare networks and cause maximum damage.<\/p>\n

    Easy Targets: <\/strong>It is also important to note that 11 low-scoring vulnerabilities exist in these products – the ones that will most likely be sidelined amongst the never-ending list of higher severity ones.<\/p>\n

    High Chatter: <\/strong>12 of the healthcare vulnerabilities have been observed as having high interest in the deep and dark web, with multiple posts discussing them – an indication that the vulnerability is being observed as a candidate for exploitation.<\/p>\n

    Attackers\u2019 Prize:<\/strong> Eight healthcare vulnerabilities fall under the RCE\/PE exploit category, implying that they can be remotely exploited to execute custom code, or easily used to elevate privileges to change the specified behavior of systems.<\/p>\n

    A Product Perspective:<\/strong> The whopping majority of vulnerabilities observed in our study are present in software applications regularly used in the healthcare industry. Hardware equipment takes the second spot with 30% affected products, followed by operating systems.<\/p>\n

    <\/p>\n

    Vulnerability Exploitation:<\/strong> CSW has been tracking healthcare vulnerabilities for a long time now and predicts their probability of exploitation, based on threat chatter, hacker activities, and exploits published, among a host of other parameters. According to our analysis, 29% of the vulnerabilities are 38 times more likely to be exploited, and this serves as a dire warning for healthcare institutions that are yet to invest in a cybersecurity strategy.<\/p>\n

    <\/p>\n

    Organizations that are unaware of the existence of such vulnerabilities in their network will remain exposed to malicious attackers. A continuous and exposure-aware attack surface management<\/a> platform can help discover such undetected attack vectors and address them in time.<\/strong><\/p>\n

    Six vulnerabilities in healthcare-related products have known associations with ransomware and APT groups. This translates to attackers having a tried and tested method that can create maximum disruption, thus marking them as highly dangerous.<\/p><\/blockquote>\n

    The products exploited by these ransomware\/APT groups are one hospitals worldwide would use for convenience and better diagnosis, without a second thought. Imagine the horror if a ransomware group attacks a hospital, encrypts all files, and demands a huge ransom payout. Most government healthcare institutions would not be in a position to pay the ransom, or have a backup that they can fall back on. On the other hand, an APT actor getting hold of such confidential information can serve as fodder for state-sponsored espionage activities.
    \nAPT Group Associations<\/strong><\/p>\n

    Our analysis associates three products as having vulnerabilities that have been previously exploited by popular threat actors, aka APT groups. Incidentally, all the four vulnerabilities are present in Oracle\u2019s products; and all of these are associated with the APT1 or the BrownFox group, a Chinese-sponsored actor in existence since 2006.<\/p>\n\n\n\n\n\n\n<\/colgroup>\n\n\n\n\n\n\n\n
    \n

    \u00a0Vendor<\/p>\n<\/th>\n

    \n

    Product<\/p>\n<\/th>\n

    \n

    Product Type<\/p>\n<\/th>\n

    \n

    Vulnerability<\/p>\n<\/th>\n

    \n

    APT Association<\/p>\n<\/th>\n<\/tr>\n<\/thead>\n

    \n

    Oracle<\/p>\n<\/td>\n

    \n

    Healthcare Foundation<\/p>\n<\/td>\n

    \n

    Application<\/p>\n<\/td>\n

    \n

    CVE-2020-11022<\/p>\n<\/td>\n

    \n

    APT1<\/p>\n<\/td>\n<\/tr>\n

    \n

    Oracle<\/p>\n<\/td>\n

    \n

    Health Sciences Inform, Healthcare Translational Research<\/p>\n<\/td>\n

    \n

    Application<\/p>\n<\/td>\n

    \n

    \u00a0CVE-2020-11023<\/p>\n<\/td>\n

    \n

    APT1<\/p>\n<\/td>\n<\/tr>\n

    \n

    Oracle<\/p>\n<\/td>\n

    \n

    Healthcare Translational Research, Healthcare Foundation<\/p>\n<\/td>\n

    \n

    Application<\/p>\n<\/td>\n

    \n

    CVE-2015-9251<\/p>\n<\/td>\n

    \n

    APT1<\/p>\n<\/td>\n<\/tr>\n

    \n

    Oracle<\/p>\n<\/td>\n

    \n

    Healthcare Translational Research, Healthcare Foundation<\/p>\n<\/td>\n

    \n

    Application<\/p>\n<\/td>\n

    \n

    CVE-2019-11358<\/p>\n<\/td>\n

    \n

    APT1<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n

     <\/p>\n

    Ransomware Associations<\/strong><\/p>\n

    Two vendors and five healthcare products have two ransomware vulnerabilities. Stryker\u2019s navigation platforms that are used in surgeries have the dangerous PrintNightmare<\/a> vulnerability that is associated with three ransomware groups, including the highly active Conti<\/a> ransomware. An attack on these devices can impede surgeries, leading to fatal consequences.<\/p>\n\n\n\n\n\n\n<\/colgroup>\n\n\n\n\n\n
    \n

    Vendor<\/p>\n<\/th>\n

    \n

    Product<\/p>\n<\/th>\n

    \n

    Product Type<\/p>\n<\/th>\n

    \n

    Vulnerability<\/p>\n<\/th>\n

    \n

    \u00a0Ransomware Association<\/p>\n<\/th>\n<\/tr>\n<\/thead>\n

    \n

    \u00a0Biomerieux<\/p>\n<\/td>\n

    \n

    Biomerieux<\/p>\n<\/td>\n

    \n

    \u00a0Operating System<\/p>\n<\/td>\n

    \n

    CVE-2020-0601<\/p>\n<\/td>\n

    \n

    BigBossHorse<\/p>\n<\/td>\n<\/tr>\n

    \n

    Stryker<\/p>\n<\/td>\n

    \n

    ADAPT Platform, Nav3i Platform, Nav3 Platform, Scopis ENU<\/p>\n<\/td>\n

    \n

    Application<\/p>\n<\/td>\n

    \n

    \u00a0CVE-2021-34527<\/p>\n<\/td>\n

    \n

    Cerber, Conti,
    \nVice Society<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n

     <\/p>\n

    CSW\u2019s Ransomware Index Report for the first quarter of 2022 flagged 310 vulnerabilities dangerously deployed by ransomware groups. Read the full report here<\/a>.<\/strong><\/p>\n

    Why should Healthcare organizations be worried about these vulnerabilities?<\/h2>\n

    Healthcare, as a sector, is classified by the US Government as one of the 16 critical infrastructures that is vulnerable to cyber-attacks. Considering how crucial the healthcare industry is, an attack on any healthcare provider has the potential to lead to disastrous consequences – from disrupting administrational activities to hampering patient care.<\/p>\n

    On the other hand, attackers have long found it profitable to force the hand of healthcare centers and hospitals to pay ransom for their patient data. Thus, it is not surprising that the sector has seen several significant attacks in the past year,\u00a0 for example, the Ireland healthcare attack<\/a> that impacted regular functioning for over a week.<\/p>\n

     <\/p>\n

    Patients can be impacted directly as well as indirectly when an attacker affects the operations of a healthcare institution. Here are some ways in which patients may be impacted by dangerous vulnerabilities.<\/strong><\/p>\n

      \n
    1. \n

      Leaked Personal Information<\/p>\n<\/li>\n<\/ol>\n