URGENT/11 Vulnerabilities: Taking Action

URGENT/11 Vulnerabilities: Taking Action

Healthcare organizations can take steps to start mitigating risks while waiting for vendors to issue software patches to address URGENT/11 IPnet vulnerabilities in medical devices, says researcher Ben Seri of the security firm Armis, which identified the flaws.

The U.S. Food and Drug Administration and the Department of Homeland Security recently issued alerts about the vulnerabilities.

The problems exist in IPnet, a third-party software component that supports network communications and is embedded into a variety of legacy medical and industrial devices that are still in use today, despite the software, in many cases, being no longer supported by the original vendors (see FDA Issues Alert on Medical Device IPnet Vulnerabilities).

The collection of URGENT/11 vulnerabilities was first identified by Armis researchers in July as affecting some versions of the real-time operating system VxWorks by Wind River.

But on Oct. 1, the FDA issued its alert, and the DHS updated an earlier advisory after Armis researchers identified six additional real-time operating systems supporting the IPnet TCP/IP stack that are also potentially impacted by the URGENT/11 vulnerabilities.

Exploitation of the vulnerabilities could lead to remote code execution and allow an attacker to take over a whole device without interacting with the user, posing potential harm to patients if a medical device subsequently malfunctions.




Next Article

  • How Hospitals Are Using AI to Detect and Treat Sepsis

    How Hospitals Are Using AI to Detect and Treat Sepsis

    Responsible for more than 270,000 annual deaths in the U.S., sepsis claims a life in this country every two minutes. The condition, which arises from the body’s inflammatory response to infection, …

    Posted Oct 7, 2019ai

Did you find this useful?

Medigy Innovation Network

Connecting innovation decision makers to authoritative information, institutions, people and insights.

Medigy Logo

The latest News, Insights & Events

Medigy accurately delivers healthcare and technology information, news and insight from around the world.

The best products, services & solutions

Medigy surfaces the world's best crowdsourced health tech offerings with social interactions and peer reviews.


© 2024 Netspective Media LLC. All Rights Reserved.

Built on Apr 26, 2024 at 6:14am