FDA Explains Urgent/11 Cybersecurity Vulnerability

Share

FDA is informing patients, healthcare professionals, IT staff in healthcare facilities, and manufacturers about the Urgent/11 cybersecurity vulnerabilities that, if exploited by a remote attacker, “may introduce risks for medical devices and hospital networks.” An online notice says that Urgent/11 affects several operating systems that may then affect certain medical devices connected to a communications network, such as wi-fi and public or home Internet, as well as other connected equipment such as routers, connected phones, and other critical infrastructure equipment.

“These cybersecurity vulnerabilities may allow a remote user to take control of a medical device and change its function, cause denial of service, or cause information leaks or logical flaws, which may prevent a device from functioning properly or at all,” the agency notice says.

FDA says that to date it has not received any adverse event reports associated with the vulnerabilities. It says the Urgent/11 vulnerabilities exist in a third-party software called IPnet that computers use to communicate with each other over a network. “The agency is asking manufacturers to work with healthcare providers to determine which medical devices, either in their healthcare facility or used by their patients, could be affected by Urgent/11 and develop risk mitigation plans,” the notice says.

Read more