{"id":3609,"date":"2024-05-16T13:56:40","date_gmt":"2024-05-16T18:56:40","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/ge-ultrasound-gear-riddled-with-bugs-open-to-ransomware-data-theft"},"modified":"2024-05-16T13:56:40","modified_gmt":"2024-05-16T18:56:40","slug":"ge-ultrasound-gear-riddled-with-bugs-open-to-ransomware-amp-data-theft","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/16\/ge-ultrasound-gear-riddled-with-bugs-open-to-ransomware-amp-data-theft\/","title":{"rendered":"GE Ultrasound Gear Riddled With Bugs, Open to Ransomware &amp;amp; Data Theft"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt11d4bf6ceecd0c39\/66465007512226e1ecef3f4e\/Ultrasound-maximimages.com-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/ge-ultrasound-gear-riddled-with-bugs-open-to-ransomware-amp-data-theft.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/ge-ultrasound-gear-riddled-with-bugs-open-to-ransomware-amp-data-theft.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Researchers have discovered 11 security vulnerabilities in GE HealthCare&#8217;s Vivid Ultrasound family of products, as well as two related software programs.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The issues are varied, and include missing encryption of sensitive data, use of hardcoded credentials, and more. They range in severity from 5.7 to 9.6 on the CVSS 3.1 scoring system.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As Nozomi Networks <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.nozominetworks.com\/blog\/ge-healthcare-vivid-ultrasound-vulnerabilities\" rel=\"noopener\">explained in its report<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, the bugs could lead to remote code execution (RCE) with full privileges and any number of attack scenarios such powers would entail. However, the most serious case scenarios also require physical access to the devices in question, massively reducing the potential risk for healthcare facilities.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Bad News\">The Bad News<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the course of their study, Nozomi&#8217;s researchers analyzed three GE creations: the Vivid T9 ultrasound system, designed primarily for cardiac imaging; its pre-installed Common Service Desktop Web application, used for various administrative purposes; and the EchoPAC clinical software package, which doctors use to review and analyze ultrasound images.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In some ways, GE&#8217;s ultrasounds are built to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/the-fda-medical-device-cybersecurity-overhaul-real-teeth\" rel=\"noopener\">prevent users from causing security issues<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. For example, the Common Service Desktop Web app is exposed only on the localhost interface of a device, preventing long-distance tampering. This is important, as the software is used by administrators to do such things as change passwords and gather logs.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Other secure design elements didn&#8217;t hold up so well, however.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Vivid T9 is essentially a complete PC running a GE-customized version of Windows 10. To focus its use in healthcare settings, most of the device logic is handled by applications and scripts running on it. Its graphical user interface (GUI), for example, restricts users from accessing the underlying operating system functionalities, with a few exceptions.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, thanks to an old bug in the system \u2014 CVE-2020-6977, a CVSS 8.4-rated kiosk breakout vulnerability \u2014 researchers were able to bypass the GUI to reach into the PC and obtain administrative privileges. Then, using CVE-2024-1628, an 8.4-severity command injection issue in Common Service Desktop, they were able to perform arbitrary code execution, dropping ransomware that froze the machine.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Exploiting EchoPAC proved even simpler, provided the program&#8217;s &#8220;Share&#8221; feature was enabled. With a connection to a doctor&#8217;s workstation, an attacker can abuse hardcoded credentials \u2014 CVE-2024-27107, critical 9.6 CVSS \u2014 to access its live database server instance. There, they can read, edit, and steal patient data.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Good News\">The Good News<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The catch is that, unlike with <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/iot\/medical-devices-on-the-iot-put-lives-at-risk\" rel=\"noopener\">Internet of Things (IoT)-connected medical devices<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, exploiting a T9 and Common Service Desktop requires that a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/inside-job-cyber-exec-admits-to-hospital-hacks\" rel=\"noopener\">malicious insider<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> have physical access to the device&#8217;s embedded keyboard and trackpad. (EchoPAC, meanwhile, is easier to break into, requiring only a foothold in the local area network and no other credentials whatsoever.)<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This is good news for healthcare facilities, but there&#8217;s also a caveat: An attacker could avoid all the necessary clicking and typing by instead plugging a malicious drive into the T9&#8217;s exposed USB port. In its experiments, Nozomi demonstrated how a specially crafted drive could compromise a T9 in only a minute&#8217;s time. For this reason, Nozomi recommends that medical professionals avoid leaving ultrasound devices unattended.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Patches and mitigations for all 11 vulnerabilities are available at GE HealthCare&#8217;s <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.gehealthcare.com\/services\/lifecycle-management\/product-security-portal\/security\" rel=\"noopener\">product security portal<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/ge-ultrasound-gear-riddled-with-bugs-open-to-ransomware-data-theft\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Researchers have discovered 11 security vulnerabilities in GE HealthCare&#8217;s Vivid<\/p>\n","protected":false},"author":12,"featured_media":3610,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3609","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/ge-ultrasound-gear-riddled-with-bugs-open-to-ransomware-amp-data-theft-scaled.jpg?fit=2560%2C1972&ssl=1",2560,1972,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/ge-ultrasound-gear-riddled-with-bugs-open-to-ransomware-amp-data-theft-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/ge-ultrasound-gear-riddled-with-bugs-open-to-ransomware-amp-data-theft-scaled.jpg?fit=300%2C231&ssl=1",300,231,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/ge-ultrasound-gear-riddled-with-bugs-open-to-ransomware-amp-data-theft-scaled.jpg?fit=640%2C493&ssl=1",640,493,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/ge-ultrasound-gear-riddled-with-bugs-open-to-ransomware-amp-data-theft-scaled.jpg?fit=640%2C493&ssl=1",640,493,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/ge-ultrasound-gear-riddled-with-bugs-open-to-ransomware-amp-data-theft-scaled.jpg?fit=1536%2C1183&ssl=1",1536,1183,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/ge-ultrasound-gear-riddled-with-bugs-open-to-ransomware-amp-data-theft-scaled.jpg?fit=2048%2C1577&ssl=1",2048,1577,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/ge-ultrasound-gear-riddled-with-bugs-open-to-ransomware-amp-data-theft-scaled.jpg?fit=1024%2C789&ssl=1",1024,789,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/ge-ultrasound-gear-riddled-with-bugs-open-to-ransomware-amp-data-theft-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/ge-ultrasound-gear-riddled-with-bugs-open-to-ransomware-amp-data-theft-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/ge-ultrasound-gear-riddled-with-bugs-open-to-ransomware-amp-data-theft-scaled.jpg?fit=2560%2C1972&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3609","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3609"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3609\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3610"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3609"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3609"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3609"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}