Access:7 - Forescout (2024)

Access:7 - Forescout (1)

Access:7 - Forescout (2)

How Supply Chain Vulnerabilities Can Allow Unwelcomed Access to Medical and IoT Devices

Forescout’s Vedere Labs and CyberMDX discovered seven supply chain vulnerabilities, including three that are rated critical by CISA, that affect PTC’s Axeda agent. The vulnerabilities impact medical and IoT devices that present an immediate risk to healthcare organizations, as well as the financial services and manufacturing sector.

Access:7 - Forescout (7)

The Impact of Access:7

The Axeda solution enables device manufacturers to remotely access and manage connected devices. Access:7 could enable hackers to remotely execute malicious code, access sensitive data or alter configuration on medical and IoT devices running PTC’s Axeda remote code and management agent.

Over 150 device models from more than 100 device manufacturers are potentially affected by Access:7. Over half of the affected device vendors belong to the healthcare industry (55%), followed by almost a quarter (24%) that develop IoT solutions. The vulnerabilities were found most often in medical imaging (36%) and laboratory (31%) machines.

This disclosure illustrates the problems with supply chain components that Forescout identified in Project Memoria, but this time in a remote management solution.

Dive into the Research

Learn what happens when vulnerabilities in remote access and management agents designed to expedite service on medical and IoT devices are exploited by hackers. This report discloses vulnerabilities in PTC’s Axeda agent, the main findings, common attack scenarios, impact on healthcare and other industries, and mitigation recommendations for device manufacturers and network operators.

Risk Mitigation Strategies

Complete protection against Access:7 requires patching devices running the vulnerable versions of the Axeda components. PTC has released its official patches and device manufacturers using this software should provide their own updates to customers. More details for device manufacturers and network operators are available in our technical report.

Access:7 - Forescout (8)

Access:7 - Forescout (9)

How Forescout Can Help

With the recent acquisition of CyberMDX, Forescout healthcare customers can use CyberMDX’s solution to identify vulnerable medical and IoT devices. The solution automatically detects the medical assets within your network and organizes them in an accessible inventory listing. Assets affected by Access:7 will appear in the Vulnerabilities Cyber Risks screen. Using the CyberMDX Control Center, customers can also track the number of affected devices and follow the progress of remediation.

The Forescout platform also protects against Access:7 vulnerabilities as follows:

eyeSight uses the Security Policy Templates (SPTs) module to identify and group vulnerable and potentially vulnerable devices. A new version of the SPT package, which can identify devices vulnerable to Access:7, can be downloaded here.

eyeInspect uses a new Access:7 Monitor script to identify vulnerable devices and detect exploitation attempts against them.

Learn More

Access:7 - Forescout (10)

Access:7 Supply Chain Vulnerabilities: What to Know and How to Mitigate the Risk

Hear from the researchers to understand:

  • What makes supply chain components so vulnerable and how to increase your awareness
  • How Access:7 impacts the healthcare industry as well as financial services and manufacturing organizations
  • Immediate actions device manufacturers and network administrators should take to mitigate your risk

Forescout Products

Get the capabilities you need to build a tailored security solution for your Enterprise of Things
and the ability to orchestrate actions to reduce cyber risk.

eyeSight

Assess Your Risk: Finding Vulnerable Devices

eyeSight

eyeInspect

Identify Attacks: Detecting Ongoing Exploits

eyeInspect

eyeSegment

Protect Your Organization: Segmenting the Network

eyeSegment

Access:7 - Forescout (2024)
Top Articles
Mobile Wallet vs UPI: Meaning and Differences | Bajaj Finserv
Tax in the Netherlands | Netherlands Tax Guide - HSBC Expat
Sprinter Tyrone's Unblocked Games
Part time Jobs in El Paso; Texas that pay $15, $25, $30, $40, $50, $60 an hour online
Comcast Xfinity Outage in Kipton, Ohio
Walgreens Alma School And Dynamite
How to Watch Braves vs. Dodgers: TV Channel & Live Stream - September 15
อพาร์ทเมนต์ 2 ห้องนอนในเกาะโคเปนเฮเกน
Aktuelle Fahrzeuge von Autohaus Schlögl GmbH & Co. KG in Traunreut
Bjork & Zhulkie Funeral Home Obituaries
Simon Montefiore artikelen kopen? Alle artikelen online
Guidewheel lands $9M Series A-1 for SaaS that boosts manufacturing and trims carbon emissions | TechCrunch
Diesel Mechanic Jobs Near Me Hiring
Kürtçe Doğum Günü Sözleri
Cambridge Assessor Database
Prosser Dam Fish Count
Wausau Obits Legacy
Ibukunore
V-Pay: Sicherheit, Kosten und Alternativen - BankingGeek
Wausau Marketplace
Trivago Sf
Curry Ford Accident Today
Riherds Ky Scoreboard
Little Rock Skipthegames
Shreveport City Warrants Lookup
Conscious Cloud Dispensary Photos
Wonder Film Wiki
Enduring Word John 15
Joann Fabrics Lexington Sc
Sacramento Craigslist Cars And Trucks - By Owner
Ryujinx Firmware 15
Bfri Forum
How To Make Infinity On Calculator
RFK Jr., in Glendale, says he's under investigation for 'collecting a whale specimen'
Royals op zondag - "Een advertentie voor Center Parcs" of wat moeten we denken van de laatste video van prinses Kate?
John F Slater Funeral Home Brentwood
Missouri State Highway Patrol Will Utilize Acadis to Improve Curriculum and Testing Management
Google Chrome-webbrowser
Cygenoth
Sukihana Backshots
Davis Fire Friday live updates: Community meeting set for 7 p.m. with Lombardo
Low Tide In Twilight Manga Chapter 53
Setx Sports
Autum Catholic Store
Lucifer Morningstar Wiki
Craigslist/Nashville
Ups Authorized Shipping Provider Price Photos
Mega Millions Lottery - Winning Numbers & Results
View From My Seat Madison Square Garden
Maurices Thanks Crossword Clue
Billings City Landfill Hours
Overstock Comenity Login
Latest Posts
Article information

Author: Horacio Brakus JD

Last Updated:

Views: 5734

Rating: 4 / 5 (71 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Horacio Brakus JD

Birthday: 1999-08-21

Address: Apt. 524 43384 Minnie Prairie, South Edda, MA 62804

Phone: +5931039998219

Job: Sales Strategist

Hobby: Sculling, Kitesurfing, Orienteering, Painting, Computer programming, Creative writing, Scuba diving

Introduction: My name is Horacio Brakus JD, I am a lively, splendid, jolly, vivacious, vast, cheerful, agreeable person who loves writing and wants to share my knowledge and understanding with you.