Zoll Defibrillator Dashboard would execute contents of random Excel files ordinary users could import
- Reference: 1623780968
- News link: https://www.theregister.co.uk/2021/06/15/zoll_defibrillator_dashboard_vulnerabilities/
- Source link:
Or so warned the US's [1]Cybersecurity and Infrastructure Security Agency , which said the Defibrillator Dashboard software, made by medical devices firm Zoll, contained six flaws in total, the combined effect of which could present an infosec Swiss cheese for malicious people to exploit.
As well as allowing low-privileged users to upload files that the dashboard software would then execute, it was saving user credentials in plaintext, stored passwords in "a recoverable format" permitting their extraction from web browsers, and was also vulnerable to cross-site scripting (XSS) attacks.
[2]
Rated at 9.9 on the CVSS v3.0 severity scale, the file upload vuln (CVE-2021-27489) could be invoked by an ordinary user. Further details have not yet been made public. Another vuln, CVE-2021-27481, was described as the dashboard using a hardcoded encryption key "in the data exchange process."
[3]
[4]
Zoll's product is used to manage fleets of defibrillators, life-saving electric shock devices used to detect the irregular heart rhythm (arrhythmia) when people are suffering a cardiac arrest and shock them back to a normal rhythm. According to the company's [5]website , its defibrillators carry out daily self-tests and report the result to the central dashboard software: "If the state of readiness of any R Series is compromised, email notifications are automatically sent to appropriate personnel – as many people as you choose. And you can view the status of the fleet at any time, from any mobile device anywhere."
[6]Feds seize two domains used by SolarWinds intruders for malware spear-phishing op
[7]Have I Been Pwned goes open source, bags help from FBI
[8]Russian gang behind SolarWinds hack returns with phishing attack disguised as mail from US aid agency
[9]SAP: It takes exploit devs about 72 hours to turn one of our security patches into a weapon against customers
The dashboard accepts uploads of Excel spreadsheets ("Save time by importing defibrillator fleet information with Microsoft® Excel files") and can export data in the same format. CISA listed the vulns in an [10]advisory note setting out the six flaws along with brief details.
Zoll had not responded to a request for comment from The Register by the time of publication. NHS Digital said it was investigating how many instances of Zoll Defibrillator Dashboard had been deployed across the British state-run health service's estate. Zoll has an active sales presence in the UK and its defibrillator products are listed on several online medical device shops.
Ian Thornton-Trump, CISO of threat intel firm Cyjax, told The Register : "The major point of this announcement is in my mind to bring attention to the nexus of medical IoT technology and human safety. It confirms Josh Coreman's work and the I am the Cavalry organization's mission," referring to a US-based medical IoT security advocacy group.
[11]
A decade ago infosec bod Barnaby Jack, of ATM jackpotting fame, warned that wireless attacks against implanted defibrillators [12]could potentially kill their human hosts . In 2019, a CVE was issued for a vuln that potentially [13]allowed tampering with wireless data flowing between pacemakers and their external controllers.
While the impact of the Zoll vulnerabilities is far from lethal, medical cybersecurity is an under-scrutinised field that has plenty of opportunities for criminals people to exploit. For example, compromising Zoll's software could provide a foothold into the victim's network allowing further exploitation in a supply-chain attack. Those are a real and growing threat, as [14]the SolarWinds and Microsoft Exchange Server compromises showed . ®
Get our [15]Tech Resources
[1] https://us-cert.cisa.gov/ics/advisories/icsma-21-161-01
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YMki-yLOwrA8zyTFfa59qAAAANM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YMki-yLOwrA8zyTFfa59qAAAANM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YMki-yLOwrA8zyTFfa59qAAAANM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.zoll.com/products/data/hospital/defibrillator-dashboard-r-series
[6] https://www.theregister.com/2021/06/02/feds_seize_nobelium/
[7] https://www.theregister.com/2021/06/01/in_brief_security/
[8] https://www.theregister.com/2021/05/28/solar_winds_attacker_nobelium_returns/
[9] https://www.theregister.com/2021/04/06/sap_patch_attacks/
[10] https://us-cert.cisa.gov/ics/advisories/icsma-21-161-01
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YMki-yLOwrA8zyTFfa59qAAAANM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[12] https://www.theregister.com/2012/10/17/pacemakers_open_to_wireless_attack/
[13] https://www.theregister.com/2019/03/22/medtronic_implanted_defibrillator_hackable/
[14] https://www.theregister.com/2021/04/19/federal_solarwinds_investigation/
[15] https://whitepapers.theregister.com/
Re: Excel
Summary of my experiences installing/upgrading ERP/MRP/CRM systems
Director: "And get rid of all that Excel stuff - I want everything on the new system. We can't afford to be shifting stuff back and forth between Excel and if Anna leaves no-one knows how to compile the reports cos she wrote all those macros that no one understands"
Team: "These are the costs of customizing the vanilla product to match our current processes."
Director: "Bugger that. There's nothing special about what we do so we'll change our processes to fit the vanilla product. "
.... vanilla system installed, processes changed, all tested, gone live, things running smoothly......
Director, waving powerpoint full of Excel charts: "I need the report that looks like this for this quarter"
Team: "We can't do that because you wouldn't pay for customization or for the OLAP add-on"
Director: "But I need it tomorrow for the board meeting. Just do it all in Excel"
Team "...anyone got Anna's phone number?"
Re: Excel
I see "Purchase Orders" arrive as Excel spreadsheets every week or two although these days more of the infection attempts arrive as Purchase_Order.HTML ... occasionally they are real. To keep everyone safe I block all suspect attachments in the mail-server and only release them after a detailed check.
Quite frankly, I find this shocking…
Ah…
..but is this current? (sorry)
Upgrade to a Derillator
No more fibs.
Going home
I'm having a bit of trouble with the concept of fleets of defibrillators controlled by Excel spreadsheets. Am I misreading something? No?
Look, I wasn't all that wild about the parallel universe I was living in. In fact, it looked to be wall-to-wall crackpots back there. But I'm clearly not cut out for this one. Can anyone provide me with instructions for returning home where my biggest worry was whether Covid vaccine would magnetize me?
Excel
As has been suggested many times on the Register's comments sections, there needs to be a serious review of the uses of Excel in organisations' IT.