• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
  • Advertise
  • Subscribe

MassDevice

The Medical Device Business Journal — Medical Device News & Articles | MassDevice

  • Latest News
  • Technologies
    • Artificial Intelligence (AI)
    • Cardiovascular
    • Orthopedics
    • Neurological
    • Diabetes
    • Surgical Robotics
  • Business & Finance
    • Wall Street Beat
    • Earnings Reports
    • Funding Roundup
    • Mergers & Acquisitions
    • Initial Public Offering (IPO)
    • Legal News
    • Personnel Moves
    • Medtech 100 Stock Index
  • Regulatory & Compliance
    • Food & Drug Administration (FDA)
    • Recalls
    • 510(k)
    • Pre-Market Approval (PMA)
    • MDSAP
    • Clinical Trials
  • Special Content
    • Special Reports
    • In-Depth Coverage
    • DeviceTalks
  • Podcasts
    • MassDevice Fast Five
    • DeviceTalks Weekly
    • OEM Talks
      • AbbottTalks
      • Boston ScientificTalks
      • DeviceTalks AI
      • IntuitiveTalks
      • MedtechWOMEN Talks
      • MedtronicTalks
      • Neuro Innovation Talks
      • Ortho Innovation Talks
      • Structural Heart Talks
      • StrykerTalks
  • Resources
    • About MassDevice
    • DeviceTalks
    • Newsletter Signup
    • Leadership in Medtech
    • Manufacturers & Suppliers Search
    • MedTech100 Index
    • Videos
    • Webinars
    • Whitepapers
    • Voices
Home » U.S. Homeland Security Dept. warns on cybersecurity risk with BD subsidiary CareFusion’s Pyxis

U.S. Homeland Security Dept. warns on cybersecurity risk with BD subsidiary CareFusion’s Pyxis

April 1, 2016 By Brad Perriello

Becton Dickinson, CareFusion

Updated to correctly label the Pyxis as a medical supply cabinet, as it was originally mislabeled as a drug dispensing cabinet.

The U.S. Homeland Security Dept. warned about more than 1,400 cybersecurity flaws found in 3rd-party software used with the Pyxis SupplyStation automated medical supply cabinet made by Becton Dickinson & Co. (NYSE:BDX) subsidiary CareFusion.

The flaws, uncovered by independent researchers Billy Rios and Mike Ahmadi in collaboration with CareFusion, could be exploited remotely and are publicly available, according to the national security agency’s Industrial Control Systems Cyber Emergency Response Team.

The vulnerabilities, found in 7 3rd-party software packs, are included with Microsoft Windows XP, Sybase SQL Anywhere 9, Symantec Antivirus 9 and Symantec pcAnywhere 10.5.

“Exploitation of these vulnerabilities may allow a remote attacker to compromise the Pyxis SupplyStation system,” according to ICS-CERT. “As a result of the identified vulnerabilities, CareFusion has started reissuing targeted customer communications, advising customers of end-of-life versions with an upgrade path. For customers not pursuing the remediation path of upgrading devices, CareFusion has provided compensating measures to help reduce the risk of exploitation.”

Customers who are still using the outdated 3rd-party software should isolate their Pyxis SupplyStation systems from the Internet or use a virtual private network to connect the devices.

Filed Under: Hospital Care Tagged With: becton dickinson, CareFusion Corp., Cybersecurity

More recent news

  • Cognixion, Blackrock Neurotech ink distro deal for BCI tech
  • AdvaMed calls for medtech tariff exemptions at Senate hearing
  • GE HealthCare, Raydiant Oximetry partner on fetal oxygen saturation tech
  • Terumo Neuro launches new stroke catheter in the U.S.
  • EnVVeno has first-in-human heart valve data, expects FDA decision this year

Primary Sidebar

“md
EXPAND YOUR KNOWLEDGE AND STAY CONNECTED
Get the latest med device regulatory, business and technology news.

DeviceTalks Weekly

See More >

MEDTECH 100 Stock INDEX

Medtech 100 logo
Market Summary > Current Price
The MedTech 100 is a financial index calculated using the BIG100 companies covered in Medical Design and Outsourcing.
MDO ad

Footer

MASSDEVICE MEDICAL NETWORK

DeviceTalks
Drug Delivery Business News
Medical Design & Outsourcing
Medical Tubing + Extrusion
Drug Discovery & Development
Pharmaceutical Processing World
MedTech 100 Index
R&D World
Medical Design Sourcing

DeviceTalks Webinars, Podcasts, & Discussions

Attend our Monthly Webinars
Listen to our Weekly Podcasts
Join our DeviceTalks Tuesdays Discussion

MASSDEVICE

Subscribe to MassDevice E-Newsletter
Advertise with us
About
Contact us

Copyright © 2025 · WTWH Media LLC and its licensors. All rights reserved.
The material on this site may not be reproduced, distributed, transmitted, cached or otherwise used, except with the prior written permission of WTWH Media.

Privacy Policy