Critical security vulnerabilities put millions of healthcare devices at risk

Healthcare
(Image credit: Shutterstock)

Cybersecurity researchers have revealed over a dozen critical vulnerabilities, which they believe could be present in millions of healthcare devices, and could help facilitate all kinds of attacks including remote code execution, denial of service attacks and data leak.

Dubbed NUCLEUS:13, the 13 vulnerabilities affecting the Nucleus TCP/IP stack were discovered by researchers at Forescout Research Labs.

The researchers explain that although the Nucleus TCP/IP stack was originally released in 1993, it is still widely used in critical safety devices operated by hospitals and the healthcare industry, including anesthesia machines, patient monitors, building automation systems, lighting controls and ventilation.

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

“The NUCLEUS:13 report uncovers some serious and urgent threats for the global healthcare industry if these vulnerabilities are not properly addressed and patched. At a time when many hospitals are still dealing with the impact of the pandemic, these vulnerabilities have the potential to cause even more widespread disruption,” explains Daniel dos Santos, Research Manager, Forescout Research Labs. 

Hidden for three decades

dos Santos explains that if bad actors were to exploit the bugs, they could take control and potentially shut down several critical hospital systems. 

Forescout shares that the vulnerabilities have been lying dormant for the last 30 years in millions of devices that deploy the vulnerable TCP/IP stack owned by Siemens. Analyzing devices by country, the researchers note that the UK is the third most potentially impacted country, preceded by the US and France. 

“Our advised mitigations for NUCLEUS:13 include using network segmentation to limit the network exposure of critical vulnerable devices and patching devices as vendors release their patches. Some vulnerabilities can also be mitigated by blocking or disabling support for unused protocols, such as FTP,” suggests dos Santos.

According to an advisory put out by the US Cybersecurity and Infrastructure Security Agency (CISA), Siemens has released updates for several of the affected products, and the agency recommends all healthcare users to update their devices to the latest version without delay.

Ensure your systems remain secure and updated using one of these best patch management tools

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
An image of network security icons for a network encircling a digital blue earth.
Industrial networks exposed to attack by faulty Moxa devices
Doctor working on laptop
Patient monitors may have some worrying security flaws
coding
Popular open source vulnerability scanner Nuclei forced to patch worrying security flaw
healthcare
Software bug meant NHS information was potentially “vulnerable to hackers”
MediaTek
MediaTek reveals host of security vulnerabilities, so patch now
Skull and Bones
Experts warn DNA sequencers are vulnerable to bootkit attacks
Latest in Security
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple H3C Magic routers hit by critical severity remote command injection, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
Latest in News
Zotac Gaming RTX 5090 Graphics Card
Nvidia Blackwell stock woes are compounded by price hikes as more RTX 5090 GPUs soar in pricing, and I’m sick and tired of it all at this point
An Apple Music pink/pixellated poster advertising DJ with Apple Music
DJ with Apple Music lands, allowing subscribers to build and mix DJ sets directly from its +100 million-song catalog
The Meta Quest 3 and controllers on their charging station which is itself on a wooden desk next to a lamp
Forget Android XR, I've got my eyes on Vivo's new Meta Quest 3 competitor as it could be the most important VR headset of 2025
Samsung Galaxy S25 from the front
The Now Bar on Samsung One UI 7 is about to get a lot more useful – and could soon match Live Activities on iOS
Marvel Rivals
Marvel Rivals will get two new hero skins for Moon Knight and Black Panther this week meaning I'll now need to farm even more Units
Nvidia app
Tired of manually optimizing your games? Nvidia's new G-Assist could save you time