Axeda Cybersecurity Vulnerability Found
FDA says a cybersecurity vulnerability has been identified for the Axeda agent and desktop server used in numerous medical devices across several manufacturers. All versions of both technologies are affected, the agency says in an online notice.
The Axeda agent and desktop server are Web-based technologies that allow one or more people to securely view and operate the same remote desktop through the Internet, FDA says. The units are owned and supported by the PTC computer software company.
“Successful exploitation of this vulnerability could allow an unauthorized attacker to take full control of the host operating system, resulting in full system access, remote code execution, read/change configuration, file system read access, log information access, and a denial-of-service condition,” the notice says. “Depending on its use in the medical device, these vulnerabilities could result in changes to the operation of the medical device and impact the availability of the remote support functionality.”
The notice contains PTC recommendations for affected manufacturers.