Type of Product |
Medical Device |
TGA Recall Reference |
RC-2023-RN-01078-1 |
Product Name/Description |
Flow Family Anaesthesia systems
Flow-i: 6677200, 6677300, 6677400, 6888520, 6888530, 6888540 Flow-c: 6887700 Flow-e: 6887900
ARTG 180464 (Getinge Australia Pty Ltd - Anaesthesia system) |
Recall Action Level |
Hospital |
Recall Action Classification |
Class II |
Recall Action Commencement Date |
15/12/2023 |
Responsible Entity |
|
Reason/Issue |
Internal testing at Getinge has revealed a cybersecurity related vulnerability which potentially could lead to Denial of Service (DoS) attack, tampering or remote code execution via remote login to the Flow Family Anaesthesia systems.
This vulnerability is only possible to exploit during a short period of time of start- up and file transfer (to connected services) when the device is connected to the hospital network directly via the Ethernet port on the Flow Family Anaesthesia systems with an Ethernet cable.
If a Getinge Connect module is used, the Flow Family Anaesthesia systems is not affected by this vulnerability.
Potential hazards related to this vulnerability include the possibility to tamper with language files and remote code execution into the anaesthesia machines resulting in panel disruption during running and/or cause misleading information on the screen which may lead to inappropriate changes of settings or the need to change anaesthesia machines during the case. |
Recall Action |
Product Defect Correction |
Recall Action Instructions |
If customers have a Getinge Connect module (X10/X20) connected to the Ethernet port on the Flow Family Anaesthesia system, no action is required.
If customers have the Flow Family Anaesthesia system connected to Connected Services directly via the Ethernet port on the Flow Family Anaesthesia system, follow the steps outlined in the customer letter to reinstall the software (supplied to affected customers by Getinge).
Getinge will be providing customers with a wireless x10 Connect module as a substitute for the ethernet cable.
Customers can contact Getinge to activate Connected Services with a Getinge Connect module. |
Contact Information |
1800 438 464 - Quality.AUNZ@getinge.com - Getinge Customer Service |