GE CARESCAPE, ApexPro, and Clinical Information Center systems
Risk Summary
Successful exploitation of these vulnerabilities could occur when an attacker gains access to the mission critical (MC) and/or information exchange (IX) networks due to improper configuration or physical access to devices. An exploit could result in a loss of monitoring and/or loss of alarms during active patient monitoring. These vulnerabilities, if exploited, may allow an attacker to obtain PHI data, make changes at the operating system level of the device, with effects such as rendering the device unusable, otherwise interfering with the function of the device and/or making certain changes to alarm settings on connected patient monitors, and/or utilizing services used for remote viewing and control of devices on the network to access the clinical user interface and make changes to device settings and alarm limits, which could result in missed or unnecessary alarms or silencing of some alarms.
Remediations
- GE recommends users confirm the proper configuration of the MC and IX networks to ensure that the isolation and configuration meet the requirements listed in the Patient Monitoring Network Configuration Guide, CARESCAPE Network Configuration Guide, and product technical and service manuals. These can be obtained by contacting GE via the customer support portal with a valid support account. A properly isolated network requires an attacker to gain physical access in order to carry out an exploit.
- GE recommends that, in addition to applying network management best practices, users ensure:
Affected Vendors
Affected Products (11)
Affected Sectors
Healthcare and Public Health
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more