Alerte De Sécurité sur Xper Information Management system components and Calysto system components

Selon Department of Health, ce/cet/cette alerte de sécurité concerne un dispositif en/au/aux/à Hong Kong qui a été fabriqué par Philips Healthcare.

Qu'est-ce que c'est?

Les alertes fournissent des informations importantes et des recommandations concernant les dispositifs médicaux. Le fait qu'une alerte soit émise ne signifie pas nécessairement qu'un dispositif soit dangereux. Les alertes de sécurité, qui sont envoyées tant aux travailleurs du secteur médical qu'aux utilisateurs de ces dispositifs, peuvent inclure des rappels. Elles peuvent être rédigées par des fabricants mais aussi par des autorités en charge de la santé.

En savoir plus sur les données ici
  • Type d'événement
    Safety alert
  • Date
    2013-03-07
  • Date de publication de l'événement
    2013-03-07
  • Pays de l'événement
  • Source de l'événement
    DH
  • URL de la source de l'événement
  • Notes / Alertes
    Hong Kong data is current through September 2018. All of the data comes from the Department of Health (Hong Kong), except for the categories Manufacturer Parent Company and Product Classification.
    The Parent Company and the Product Classification were added by ICIJ.
    The parent company information is based on 2017 public records. The device classification information comes from FDA’s Product Classification by Review Panel, based on matches of data from the U.S. and Hong Kong.
  • Notes supplémentaires dans les données
    Medical Device Safety Alert
  • Cause
    Medical device field corrective action: philips xper information management system components and calysto system components medical device manufacturer,philips healthcare has initiated a medical device field correction action concerning all xper information management system components and calysto system components installed after january 2008. philips healthcare has become aware that certain default passwords loaded on a number of our devices at the factory have been recently disclosed to the general public by security researchers. if passwords for the workstation or server hosting the software are unchanged following installation, there exists the possibility of access to the operating system of the device. this could enable an unauthorized user to gain control of the operating system of the workstation and server supporting the patient monitoring system. the security researchers also demonstrated a network based heap overflow vulnerability in the xper connect broker component on port 6000 of the device. although the exploit code has not been publicly disclosed, philips healthcare is currently working on resolutions to this issue. as a temporary measure, this port can be safely firewalled to eliminate any immediate threat. the manufacturer advises users to alert the service account(s) per the facility it security protocols and contact the local philips service organization to let them know about any changes to the service account the users may have alerted or created. according to the local supplier, the affected products were distributed in hong kong. if you are in possession of the affected product, please contact your supplier for necessary actions. posted on 7 march 2013.

Device

  • Modèle / numéro de série
  • Description du dispositif
    Medical Device Safety Alert: Philips Xper Information Management system components and Calysto system components
  • Manufacturer

Manufacturer

  • Société-mère du fabricant (2017)
  • Source
    DH