According to the report, Aethon’s hospital robots, designed to transport medications, bed linens, food and laboratory specimens, contain five vulnerabilities within their base servers that can be easily hijacked.
The vulnerabilities range from allowing hackers to create new users with high-level access in order to remotely control the robots and access restricted areas or snoop on patients or guests using the robot’s in-built cameras.
To access the vulnerabilities requires a very low-skill level, but the potential risk is limited if access to the robots’ base servers are confined to a local network, with limited access only to logged-in employees, according to the report.
Peter Seiff, CEO of ST Engineering Aethon confirmed the vulnerabilities to TechCrunch and said they were fixed in a batch of software and firmware updates.
It is unknown what percentage of Aethon’s autonomous robots had been patched following the software update.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.