Some stakeholders are eagerly awaiting the full implementation of the **Cyber Resilience Act**. This legislation, aimed at strengthening the security of software and hardware suppliers, has been gradually coming into effect since June of last year, with an intermediate stage in September and full implementation scheduled for December 2027. More than a year before this deadline, which will result in obligations related to vulnerability management, from detection to correction, the Cert-FR and Cert Santé have recently published their experience report on product vulnerabilities in the healthcare sector. The objective is to remind publishers of their responsibilities.
The current state of affairs is not encouraging. A recent survey by the Health Digital Agency reports that a very high proportion of respondents (74%) are "facing publishers who delay or refuse to correct vulnerabilities." "In several cases, these vulnerabilities can be identified and exploited with a low level of technical expertise," warn the two incident response centers. In their six-page report, the two organizations highlight some (negative) concrete examples. First, there are long delays. For four publishers, the processing of a vulnerability has been ongoing "for more than a year." In one case, the deployment of the latest patch related to a medium-level vulnerability "was scheduled five years after its report."
Lack of maturity. This delay is due to several reasons. Publishers may want to integrate the patch into a product update. The software may also be present on a large number of environments, complicating the testing of the update. In other cases, it can be a communication problem with customers, a costly code refactoring, and regulatory constraints with CE marking. Additionally, some vulnerabilities should not be corrected, as they reflect a lack of consideration for security in the development of the solution. The two Certs mention, for example, secrets accessible by entering a URL. Or administrator credentials and passwords accessible in the application code. Robust authentication. Some solutions are also vulnerable to XSS attacks, through JavaScript code injection, or SQLi, with server-side code injection.
"These situations can be explained in some cases by a lack of systematic consideration of security or by the internal development of security functions," the two Certs state. The two organizations also note having identified instances of the same health software exposed on the internet and accessible without authentication. "The need for remote access can be legitimate," they agree. However, they emphasize that, in the absence of "imposing a complex or costly solution, the configuration of a robust, native, and simple authentication on such tools must be systematically implemented." Heavy fines. Regarding access control, the two Certs call for limiting each user's access "only to the actions and data that are legitimate," "according to the principle of least privilege." "User and client requests should not be satisfied at the expense of security, for example by a massive opening of access rights," they add. These are currently well-meaning reminders. Starting in December 2027, however, cyber-firefighters will indeed be able to report to the National Frequency Agency, the market oversight authority, any shortcomings by a publisher in meeting its obligations. In case of sanctions, the fine could amount up to 15 million euros or 2.5% of the publisher's annual global turnover.
Cyber Resilience Act Implementation Raises Concerns in Healthcare Sector
AI-rewritten from original reportingHow it works
cyber-resilience-acthealthcare-securityvulnerability-managementsoftware-patchesdata-protection



