HC3-TLP white Analyst Note: New DNS Vulnerabilities Impacting Healthcare Organizations April 14, 2021

On 12 April 2021, security researchers disclosed a series of medium, high and critical severity DNS vulnerabilities impacting the TCP/IP stacks present in potentially millions of enterprise and consumer devices, with organizations in the healthcare and government sectors impacted most. The flaws could enable threat actors to take affected devices offline or gain control over them. While some patches have been released and mitigations are available, many organizations may encounter hurdles applying the patches where centralized vulnerability management is not an option and many device owners may not even be aware that devices contain these vulnerable TCP/IP stacks.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

Senior Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272