The Recall Desk

FDA (Devices) recall action 88986

AMO Manufacturing USA, LLC recalled 2 products on 2022-01-05

The FDA (Devices) publishes a recall like this one as 2 separate product records. They share a firm, a date and a cause; this page is all of them in one place, so the scale of the action is visible rather than spread across 2 pages.

Products
2
Announced
2022-01-05
Critical
0
Units
1,257

Why these products were recalled

Aberrometer and precision laser systems are affected by a remote code execution vulnerability existing when the Microsoft Windows Print Spooler service is enabled, and improperly performs privileged file operations. This could be exploited to run arbitrary code with SYSTEM privileges, allowing for program installation; view/change/deleting data; or creation of new accounts with full user rights.

The agency’s own wording, quoted from the enforcement report.

The unit total adds up the quantities the agency stated for each product. Where a product record gave no figure, or gave a weight rather than a count, it contributes nothing — so the real total is at least this, never less.

States named across these recalls

1–2 of 2

  • HighFDA (Devices)··2022-01-05

    Medical Device Aberrometer Systems Affected by Remote Code Execution Vulnerability

    AMO Manufacturing's iDesign aberrometer systems (711 units, Models G300 and G301) are vulnerable to remote code execution through the Windows Print Spooler service. An attacker could run arbitrary code with SYSTEM privileges to install programs, access or delete data, or create accounts.

    Product
    iDesign, Model - G300: System AWS (International), System AWS (China), Advanced WaveScan Studio (United States); iDesign Refractive Studio Aberrometer (International) and (United States), Model: G301
    Category
    Distribution
    47 states
  • HighFDA (Devices)··2022-01-05

    Catalys Precision Laser System recalled for remote code execution vulnerability

    AMO Manufacturing is recalling Catalys Precision Laser Systems due to a Windows Print Spooler vulnerability that could allow unauthorized remote code execution with system privileges.

    Product
    Catalys Precision Laser System, Models: Catalys-U (United States), Catalys-I (International), Catalys-C (China); and Catalys Precision Laser System No Bed, Models: 0160-6020 (United States), 0160-6010 (International)
    Category
    Distribution
    47 states