3,000 Hospitals Vulnerable Due to Pneumatic Tube Flaws

80 percent of hospitals in North America use system

By Chris Miller, Assistant Editor, Facility Market


Vulnerabilities have been discovered in a pneumatic tube system used by more than 3,000 hospitals worldwide, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The report referred to nine critical weaknesses in the tube systems that allow for a complete cyber hijacking of the translogic nexus control panel, which powers the systems created by Swisslog Healthcare. More than 80 percent of hospitals in North America use the system, according to Xtelligent Healthcare Media. Pneumatic tube systems play a critical role in patient care to deliver medications, blood products, and various lab samples across multiple departments. 

A vulnerability could let in complex ransomware attacks while allowing attackers to leak sensitive hospital information. The vulnerabilities in the system, which are called PwnedPiper, can be taken advantage of to access a hospital’s network and take over Nexus control panel stations without proper verification. There has not been any evidence that cyber attackers have abused these newfound vulnerabilities.

Researchers from Armis, a California-based security vendor, found these vulnerabilities and reported them to Swisslog Healthcare on May 1, according to Becker’s Hospital Review. CISA is encouraging all hospitals with this system to take immediate defensive measures against potential cyber attacks. 

Armis gave several examples of the tube systems features and how they could be hacked.

First, the system allows for the authentication of staff members using their RFID cards, and this puts staff records and credentials at risk to potential cyber attackers if the system were to be compromised.

Second, the system supports variable speed transactions which allow for express shipment of more urgent items in one respect, and in another allow for the slow transfer of sensitive items like blood products. If an attacker infiltrated the system, he or she could alter its speed restrictions, which could then damage sensitive items.

Third, the pneumatic tube system has an alert messaging feature that integrates with hospital communications, enabling the notification and tracking of delivered carriers. If an attacker were to exploit this feature, he or she could interfere with the hospital’s workflows.



August 9, 2021


Topic Area: Information Technology


Recent Posts

Contaminants Under Foot: A Closer Look at Patient Room Floors

So-called dust bunnies on hospital room floors contain dust particles that turn out to be the major source of the bacteria humans breathe.


Power Outages Largely Driven by Extreme Weather Events

Almost half of power outages in the United States were caused by extreme weather events.


Nemours Children's Health Opens New Moseley Foundation Institute Hospital


Code Compliance Isn't Enough for Healthcare Resilience

Intensifying climate risks are pushing hospitals to think beyond code requirements and toward long-term resilience.


Ribbon Cutting Marks First Phase Completion for New Montefiore Einstein Facility

The second phase is expected to be completed in the second half of 2027.


 
 


FREE Newsletter Signup Form

News & Updates | Webcast Alerts
Building Technologies | & More!

 
 
 


All fields are required. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

 
 
 
 

Healthcare Facilities Today membership includes free email newsletters from our facility-industry brands.

Facebook   Twitter   LinkedIn   Posts

Copyright © 2023 TradePress. All rights reserved.