Blog

New medical device vulnerability: RDPV2 / DEJABLUE

Trimedx's Cybersecurity team has discovered a new cybersecurity vulnerability related to medical devices that may impact patient safety, sensitive data security, and healthcare facility operations. See the details below describing the scope and impact of the vulnerability. 

 

Vulnerability Name: RDPV2 / DEJABLUE

Source: Microsoft

Date discovered: August 15, 2019

Criticality: Low/medium/high/critical

Models impacted: List devices here.

AND/OR

Login to TRIMEDX Cyber Informatics dash to see your impacted devices.  

Description: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.   To exploit this vulnerability, an attacker would need to send a specially crafted request to the target system's Remote Desktop Service via RDP.   The update addresses the vulnerability by correcting how Remote Desktop Services handles connection requests.

Recommendation: Install OEM released patch or log in to TRIMEDX Cyber Informatics dash to see other remediation options specific to your health organization. 

Get help with this cybersecurity vulnerability: 

For existing Cybersecurity Clients, contact your cyber representative 

Not a TRIMEDX Client, contact us.  

Get the latest in news and announcements from Trimedx

Sign up below to receive monthly updates on the latest news from our team.