Flow Neuroscience FL-100

Summary

A critical vulnerability has been identified in the Flow Neuroscience FL-100 device, allowing attackers within Bluetooth range to manipulate brain stimulation parameters and override safety limits due to hard-coded credentials. Successful exploitation could impact the Healthcare and Public Health critical infrastructure sector worldwide.

IFF Assessment

FOE

The discovery of hard-coded credentials in a medical device that allows for manipulation of safety limits presents a significant risk to users and could be exploited by malicious actors.

Severity

8.1 High

Defender Context

This vulnerability highlights the risks associated with hard-coded credentials in IoT and medical devices, especially those using Bluetooth for communication. Defenders should be aware of the potential for remote manipulation of critical systems and ensure that firmware updates are applied promptly to mitigate such risks. The widespread deployment in critical infrastructure underscores the need for robust security measures in healthcare technology.

Read Full Story →