The German Federal Institute for Drugs and Medical Devices (BfArM) points out critical vulnerabilities in the real-time operating system VxWorks of Wind River. Accordingly, medical device manufacturers using this operating system must implement risk mitigation measures.
According to the German Federal Institute for Drugs and Medical Devices (BfArM), Wind River’s real-time operating system VxWorks is used in many medical devices, therefore do critical vulnerabilities in the operating system have consequences for these medical devices. Affected versions are:
Medical device manufacturers using this operating system must implement risk mitigation measures based on their updated risk analysis in light of this vulnerability.
If these measures correspond to the definition of a recall in accordance with § 2 No. 3 MPSV (a measure to eliminate, reduce or prevent the recurrence of a risk arising from a medical device, which initiates the return, replacement, retrofitting, disposal or destruction of a medical device or provides users, operators or patients with information on the further safe use or operation of medical devices), the measure must be reported to BfArM on the notification form for Field Safety Corrective Actions issued by BfArM.