Remisol Advance software recalled for remote code execution vulnerability
Normand-Info S.A.S.U. is recalling Remisol Advance software running on unsupported Windows operating systems due to a critical remote code execution vulnerability.
What this means for you
Illness, injury, or structural failure has been reported. Stop using the product immediately and contact the manufacturer for a refund or repair.
Our severity reasoning: The source text explicitly describes a 'critical remote code execution vulnerability' that allows an attacker to 'execute arbitrary code' and 'create new accounts with full user rights.' This aligns with the rubric's criterion for 'significant injury/property-damage reports' or high-risk security defects that compromise system integrity and data, warranting a Severe classification.
Plain-English summary
Normand-Info S.A.S.U. is recalling Remisol Advance software that runs on hardware with Windows XP, Windows 7, Windows Server 2003, and Windows Server 2008 operating systems. The recall involves 6,479 units distributed across 50 states and the District of Columbia. All serial numbers are affected.
The recall is due to a critical remote code execution vulnerability in remote desktop services. This vulnerability can be exploited remotely without authentication. An attacker who successfully exploits this vulnerability could execute arbitrary code on the target system, install programs, view, change, or delete data, or create new accounts with full user rights. If the vulnerability is exploited locally, it would lock down the computer.
A patch was released for this vulnerability. Users of the affected software should apply the patch to mitigate the risk of unauthorized access and data compromise.
The recalled product
- Product
- Remisol Advance running on hardware with Windows XP, Windows 7, Windows Server 2003 and Windows Server 2008 operating systems
- Manufacturer
- Normand-Info S.A.S.U.
- Category
- Medical Device — Software
- Affected units
- 6,479
Is your product affected?
Check your packaging against the codes below. If any of them match, the product is part of this recall.
Lot numbers (1)
- All serial numbers
Distribution
Related recalls
Same manufacturer · Normand-Info S.A.S.U.
See all →- HighLaboratory Software Device May Produce Erroneous Results from Inadequate Instructions
FDA (Devices) · 2021-06-16
- HighNormand-Info Remisol Advance Software Recall for Erroneous Lab Results
FDA (Devices) · 2020-08-12
Same hazard · remote code execution
See all →- HighFlow-i C40 Anesthesia System Recalled for Cybersecurity Vulnerability
FDA (Devices) · 2024-02-14
- HighAnesthesia System Cybersecurity Vulnerability Poses Denial of Service Risk
FDA (Devices) · 2024-02-14
- HighFlow-i C20 Anesthesia System cybersecurity vulnerability could enable remote attacks
FDA (Devices) · 2024-02-14
- HighFlow-c Anesthesia System cybersecurity vulnerability in 14 units
FDA (Devices) · 2024-02-14
- HighFlow-e Anesthesia System Model 6887900 Cybersecurity Vulnerability Recall
FDA (Devices) · 2024-02-14