‘PwnedPiper’: Devastating Bugs in >80% of Hospital Pneumatics
#1
Information 
Quote:Researchers have discovered nine vulnerabilities – collectively dubbed PwnedPiper – in the pneumatic tube systems (PTS) used in more than 80 percent of major hospitals in North America.
 
The bugs, in Swisslog Healthcare’s Translogic PTS, include hard-coded passwords, unencrypted connections and unauthenticated firmware updates that could lead to remote code execution (RCE). The flaws could give an unauthenticated attacker root control and could let bad actors take over Nexus stations.
 
The nine critical vulnerabilities are in the Nexus Control Panel, which powers all current models of Translogic pneumatic tube system (PTS) stations sold by Swisslog Healthcare. “All current firmware versions of this device are susceptible to these vulnerabilities,” Armis researchers said.
 
After an attacker hijacks a Nexus station, it’s all downhill from there, as Armis reported on Monday, with potential ransomware attacks in the mix. “By compromising a Nexus station, an attacker can leverage it for reconnaissance purposes, including harvesting data from the station, such as RFID credentials of any employee that uses the PTS system, details about each station’s functions or location, as well as gain an understanding of the physical layout of the PTS network,” Armis said in a release. “From there, an attacker can take over all Nexus stations in the tube network, and hold them hostage in a sophisticated ransomware attack.”

Read more: ‘PwnedPiper’: Devastating Bugs in >80% of Hospital Pneumatics | Threatpost
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Judge says Google does not need to sell ...
Last year, a U.S. ...harlan4096 — 11:05
Opera for iOS gets new tab management fe...
Opera for iOS has ...harlan4096 — 09:25
Google Chrome 140.0.7339.80/81
Google Chrome 140....harlan4096 — 09:23
Linux Mint 22.2
Linux Mint 22.2: ...harlan4096 — 07:36
Manjaro Linux 25.0.8 Build 250902
 Manjaro Linux 25....harlan4096 — 07:28

[-]
Birthdays
Today's Birthdays
avatar (39)Margieweimi
avatar (39)Larondabet
avatar ()tradedeer1
Upcoming Birthdays
avatar (38)fapedDow
avatar (48)pohudidere
avatar (40)obudyg
avatar (48)rarinsWax
avatar (25)DianaBrown
avatar (35)emyzowa
avatar (46)JustinPrede
avatar (38)eqiduseb
avatar (44)fedosmiday
avatar (41)brechTiz
avatar (47)schedZoorb
avatar (41)bgreorasjunior4824
avatar (45)ThomasLYDAY
avatar (40)upakoExapy
avatar (50)diplomasync
avatar (49)Myronjax
avatar (49)skepwHug
avatar (38)RicardoGoase
avatar (41)JaniceArods
avatar (42)Brianven
avatar (31)I3rYcE
avatar (42)Edwardgef
avatar (43)Denpokhew
avatar (35)azidony
avatar (40)maskbSleew

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>