ICS-CERT Published Advisory on Hospira Infusion System Flaws

May 14, 2015

The Department of Homeland Security’s (DHS) Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) issued an advisory announcing that version 5.0 of Hospira’s LifeCare PCA Infusion System was found vulnerable to remotely exploitable bugs.

The infusion pump device was discovered to have an improper authorization flaw, along with insufficient data authenticity verification. According to ICS-CERT, the device allows unauthorized users to modify configurations within the infusion pump. Because of the system’s vulnerability to t verification, unauthorized sources could upload drug libraries, software updates, and configuration changes to the device.

As a precaution, the DHS advised device owners to carry out prevention safety measures such as closing unused ports like Port 20/FTP and Port 23/TELNET, layering physical and logical security within environments operating medical devices, and isolating the infusion pump from the internet and untrusted systems.

“When remote access is required, use secure methods, such as VPNs, recognizing that VPNs may have vulnerabilities and should be updated to the most current version available,” the advisory said. “Also recognize that VPN is only as secure as the connected devices.”

ICS-CERT also recommended that infusion pump owners produce MD5 checksums of key files to identify any unauthorized changes.

As infusion pump technology continues to advance, it is important for clinicians and health care providers to keep their equipment well-maintained and up-to-date to ensure patient-safety. AIV is an expert in providing IV pump repair services and also offers top-quality refurbished IV pumps, replacement parts, and accessories for leading manufacturers, including Hospira. Learn more about AIV’s full line of products by visiting http://aiv-inc.com/iv-pump-parts-service.html

About the Author

Laura Collier

Laura Collier

Laura Collier has a Bachelor’s Degree in Communications and a Master’s Degree in Business Administration from the University of North Florida. She is the Marketing Manager at AIV, Inc.

AIV Catalog

Request Your Printed or Electronic Copy Today!
We Respect Your Privacy

Be Part of Our
Biomed Community

Healthcare technology management professionals are a vital link in hospital operations, and we proudly support the national, state, and local associations with ongoing support and resources.

Get Biomed Resources

Why buy from AIV

AIV strives to provide you cost effective options to service equipment. We offer flexible solutions to best suit your needs.