Welcome to 2017: Pacemaker Patients Told to Visit Doctors to Receive Security Patches

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
Patients with pacemakers manufactured by Abbott — formerly St. Jude Medical's — are advised to reach out to their doctors and inquire about the availability of a security update for their implanted medical devices.

The security update will fix three vulnerabilities discovered last year by MedSec Holdings Ltd.. The flaws are detailed in a security alert issued by the Department of Homeland Security's CERT team.

Flaws are not easy to exploit
US CERT says the flaws allow attackers to gain access to a pacemaker and issue commands, change settings, or otherwise interfere with the intended function of the pacemaker.

Despite the dire consequences, US CERT experts say the attacks are not easy to pull off, as there's no public exploit code to help attackers develop their own attack packages, and exploitation requires a high level of skills, that very few programmers possess.

In addition, attackers need to be sufficiently close (few inches) to the target pacemaker as to allow RF communications.

The flaws were discovered by MedSec, a company that Abbott is very familiar with. In September 2016, Abbott sued MedSec and fellow security company Muddy Waters, claiming the two companies organized a media stunt on the back of vulnerabilities in its pacemakers. Those flaws, detailed here, were eventually fixed in January 2017.

Read More. Welcome to 2017: Pacemaker Patients Told to Visit Doctors to Receive Security Patches
 

In2an3_PpG

Level 18
Verified
Top Poster
Content Creator
Well-known
Nov 15, 2016
867
Despite the dire consequences, US CERT experts say the attacks are not easy to pull off, as there's no public exploit code to help attackers develop their own attack packages, and exploitation requires a high level of skills, that very few programmers possess.

That's crazy to think that people that require pacemakers to necessarily live day to day need to go in for security patches. Even if it takes a lot of skill to pull off an attack. Still crazy.
 

SHvFl

Level 35
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,350
An emp and you rip. Hope i never need one because when the aliens attack they will probably use emps.

PS The above scenario is more likely than someone caring enough to hack your pacemaker and it will get harder as the danger expands.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top