MesaLabs Laboratory Temperature Monitoring System Critical Vulnerabilities

H-ISAC TLP White: June 8, 2021

ICS Advisory (ICSA-21-147-03) was recently released, which highlighted five critical vulnerabilities that have been identified in the MesaLabs AmegaView that provide continuous monitoring systems that are used in hospital laboratories, forensics labs, and biotech firms. Two of the flaws are susceptible to critical command injection vulnerabilities with CVSS severity scores of 9.9/10 and 10/10, respectively. Other known vulnerabilities include improper authentication, authentication bypass using an alternate path or channel, and improper privilege management. AmegaView products affected by the vulnerabilities include versions 3.0 and prior.

Health-ISAC is distributing this alert to augment efforts supporting the protection of critical infrastructure and the maintenance of organization security posture.

Read the full report below.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

Senior Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272