Cyber Threats to CareFusion Pyxis System
The Department of Homeland Security says that independent researchers in collaboration with CareFusion have identified numerous third-party software vulnerabilities in end-of-life versions of the company’s Pyxis SupplyStation system. Because the affected software versions are at end-of-life, the notice says, a patch will not be provided. CareFusion is providing compensating measures to help reduce the risk of exploitation for the affected versions of the system.
The affected products are automated supply cabinets used to dispense medical supplies that can document usage in real-time. The system includes automated devices that may be deployed using a variety of functional configurations. “The Pyxis SupplyStation systems have an architecture that typically includes a network of units, or workstations, located in various patient care areas throughout a facility and managed by the Pyxis SupplyCenter server, which links to the facility’s existing information systems,” the notice says.
It says that the software vulnerabilities could be exploited remotely by an attacker with low skill.