3,000 Hospitals Vulnerable Due to Pneumatic Tube Flaws

80 percent of hospitals in North America use system

By Chris Miller, Assistant Editor, Facility Market


Vulnerabilities have been discovered in a pneumatic tube system used by more than 3,000 hospitals worldwide, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The report referred to nine critical weaknesses in the tube systems that allow for a complete cyber hijacking of the translogic nexus control panel, which powers the systems created by Swisslog Healthcare. More than 80 percent of hospitals in North America use the system, according to Xtelligent Healthcare Media. Pneumatic tube systems play a critical role in patient care to deliver medications, blood products, and various lab samples across multiple departments. 

A vulnerability could let in complex ransomware attacks while allowing attackers to leak sensitive hospital information. The vulnerabilities in the system, which are called PwnedPiper, can be taken advantage of to access a hospital’s network and take over Nexus control panel stations without proper verification. There has not been any evidence that cyber attackers have abused these newfound vulnerabilities.

Researchers from Armis, a California-based security vendor, found these vulnerabilities and reported them to Swisslog Healthcare on May 1, according to Becker’s Hospital Review. CISA is encouraging all hospitals with this system to take immediate defensive measures against potential cyber attacks. 

Armis gave several examples of the tube systems features and how they could be hacked.

First, the system allows for the authentication of staff members using their RFID cards, and this puts staff records and credentials at risk to potential cyber attackers if the system were to be compromised.

Second, the system supports variable speed transactions which allow for express shipment of more urgent items in one respect, and in another allow for the slow transfer of sensitive items like blood products. If an attacker infiltrated the system, he or she could alter its speed restrictions, which could then damage sensitive items.

Third, the pneumatic tube system has an alert messaging feature that integrates with hospital communications, enabling the notification and tracking of delivered carriers. If an attacker were to exploit this feature, he or she could interfere with the hospital’s workflows.



August 9, 2021


Topic Area: Information Technology


Recent Posts

Fire at Assisted Living Facility Kills 9, Injures 30

Half of the building’s residents were evacuated through small windows.


North Carolina Children's Health Selects Apex for Campus Location

The groundbreaking is anticipated to happen in 2027.


Designing for Access: Addressing Pharmacy Deserts with Flexible Solutions

Design is an increasingly important consideration for closing the gap in pharmaceutical access.


Baylor Scott & White Health Set to Open New Texas Medical Center 

The new 40-acre campus will offer communal green spaces, more than two miles of trails, health and wellness events and activities for everyone to enjoy.


The Future of Backup Power Systems in Healthcare Facilities

Manufacturers discuss what trends are shaping the future of backup power systems in healthcare.


 
 


FREE Newsletter Signup Form

News & Updates | Webcast Alerts
Building Technologies | & More!

 
 
 


All fields are required. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

 
 
 
 

Healthcare Facilities Today membership includes free email newsletters from our facility-industry brands.

Facebook   Twitter   LinkedIn   Posts

Copyright © 2023 TradePress. All rights reserved.