HC3 TLP White Alert: Forescout Nucleus TCP/IP Stack Vulnerability Amplify Alert November 12, 2021

At A Glance

 

Executive Summary

Cybersecurity researchers at Forescout have identified 13 vulnerabilities that impact millions of Internet-connected hospital devices. Several of these vulnerabilities have been categorized as high or critical. The research includes associated patches. HC3 recommends healthcare organizations analyze their infrastructure for vulnerable devices and apply patches in a timely manner.

Report

New Critical Vulnerabilities Found on Nucleus TCP/IP Stack
https://www.forescout.com/blog/new-critical-vulnerabilities-found-on-nucleus-tcp-ip-stack/

Impact to HPH Sector

These 13 newly disclosed vulnerabilities in Nucleus Net TCP/IP stacks, dubbed Nucleus:13, could allow attackers to launch denial-of-service (DoS) attacks to disrupt medical equipment and patient monitors. Some of them allow for information leakage (both patient and technical data related to the operations of the vulnerable device) as well as remote code execution, which would allow an attacker to potentially take control of a compromised device. View the entire report below. 

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

Senior Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272