Back to all lessons
Awareness Lessons
2 months ago

Unauthenticated BLE Commands Allow Attackers to Hijack Medical Stimulator

The Pulsetto Vagus Nerve Stimulator exposes a critical flaw in its Bluetooth Low Energy implementation, allowing attackers to send hidden commands without any authentication or encryption. This means anyone within BLE range can disable safety features or alter stimulation settings on a patient's device, posing direct physical harm. The absence of a vendor response to CISA compounds the risk, leaving users with no official mitigation path. This case highlights how security-by-obscurity and unauthenticated wireless interfaces in medical devices create life-threatening attack surfaces.

Tactical Insight

Immediate actions

  • Disable or limit Bluetooth connectivity on the device when not actively in use to reduce the attack surface.
  • Users and healthcare providers should monitor CISA advisories and apply any vendor-issued patches immediately upon release.

Long-term improvements

  • Require mutual authentication and end-to-end encryption for all BLE communications in medical device firmware.
  • Mandate security testing (including wireless protocol fuzzing) as part of the medical device development and certification lifecycle.
  • Enforce vendor accountability by requiring documented incident response commitments before regulatory approval of connected medical devices.

Detection measures

  • Deploy BLE monitoring tools in clinical environments to detect anomalous or unauthorized command traffic targeting medical devices.
  • Establish a coordinated disclosure and response SLA with device manufacturers to ensure timely mitigation of reported vulnerabilities.