B
今週中
Flow Neuroscience社の脳刺激デバイス「FL-100」において、認証をバイパスできるハードコードされた資格情報の脆弱性
📌 一言でいうと
Flow Neuroscience社の脳刺激デバイス「FL-100」において、認証をバイパスできるハードコードされた資格情報の脆弱性が発見されました。攻撃者がBluetooth通信範囲内にいれば、脳刺激パラメータを任意に操作し、安全制限を上書きすることが可能です。影響を受ける製品はFL-100およびHalo Neuroscience FL-100です。
🔍該当判定
- 社内で「Flow Neuroscience FL-100」という脳刺激デバイスを導入・利用している
- 社内で「Halo Neuroscience FL-100」という脳刺激デバイスを導入・利用している
- 医療・ヘルスケア関連の業務で、上記製品を患者や従業員に使用させている
上記いずれにも該当しない → 静観でOK
✅該当時の対応
ベンダーから提供される最新のファームウェアアップデートを適用し、ハードコードされた資格情報の問題を解消してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Flow Neuroscience FL-100 (CVE-2026-18164) 対応について
お疲れさまです。Flow Neuroscience社の医療デバイスに関する脆弱性の情報共有です。
■ 概要
脳刺激デバイス FL-100 において、認証をバイパス可能なハードコードされた資格情報が発見されました (CVE-2026-18164)。CVSS v3 スコアは 8.1 と高く、Bluetooth 範囲内の攻撃者が刺激パラメータを操作し、安全制限を無効化できるリスクがあります。
■ 影響範囲
- Flow Neuroscience FL-100
- Halo Neuroscience FL-100
■ 対応手順
1. 自社または管理下で当該デバイスが利用されているか確認してください。
2. ベンダーが提供する修正パッチまたは最新ファームウェアへの更新を適用してください。
■ 参考情報
- CISA ICS Medical Advisory (ICSMA-26-225-01)
対応優先度: 高
対応期限: 速やかに
お疲れさまです。Flow Neuroscience社の医療デバイスに関する脆弱性の情報共有です。
■ 概要
脳刺激デバイス FL-100 において、認証をバイパス可能なハードコードされた資格情報が発見されました (CVE-2026-18164)。CVSS v3 スコアは 8.1 と高く、Bluetooth 範囲内の攻撃者が刺激パラメータを操作し、安全制限を無効化できるリスクがあります。
■ 影響範囲
- Flow Neuroscience FL-100
- Halo Neuroscience FL-100
■ 対応手順
1. 自社または管理下で当該デバイスが利用されているか確認してください。
2. ベンダーが提供する修正パッチまたは最新ファームウェアへの更新を適用してください。
■ 参考情報
- CISA ICS Medical Advisory (ICSMA-26-225-01)
対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] Flow Neuroscience FL-100 (CVE-2026-18164) Mitigation
Dear Team,
We are sharing technical details regarding a critical vulnerability in Flow Neuroscience devices.
■ Overview
An undocumented hard-coded credential has been identified in the Flow Neuroscience FL-100 (CVE-2026-18164), allowing authentication bypass. With a CVSS v3 score of 8.1, an attacker within Bluetooth range could manipulate brain stimulation parameters and override safety limits.
■ Affected Products
- Flow Neuroscience FL-100
- Halo Neuroscience FL-100
■ Mitigation Steps
1. Identify if these devices are in use within your environment or managed healthcare facilities.
2. Apply the latest firmware updates provided by the vendor to resolve the hard-coded credential issue.
■ Reference
- CISA ICS Medical Advisory (ICSMA-26-225-01)
Priority: High
Deadline: Immediate
Dear Team,
We are sharing technical details regarding a critical vulnerability in Flow Neuroscience devices.
■ Overview
An undocumented hard-coded credential has been identified in the Flow Neuroscience FL-100 (CVE-2026-18164), allowing authentication bypass. With a CVSS v3 score of 8.1, an attacker within Bluetooth range could manipulate brain stimulation parameters and override safety limits.
■ Affected Products
- Flow Neuroscience FL-100
- Halo Neuroscience FL-100
■ Mitigation Steps
1. Identify if these devices are in use within your environment or managed healthcare facilities.
2. Apply the latest firmware updates provided by the vendor to resolve the hard-coded credential issue.
■ Reference
- CISA ICS Medical Advisory (ICSMA-26-225-01)
Priority: High
Deadline: Immediate