Company:Roche Diagnostics Operations, Inc. .
Date of Enforcement Report 1/30/2013
Class ll:
PRODUCT
Roche COBAS INTEGRA 400 and 400 plus Analyzer The Roche COBAS INTEGRA 400/400 plus Analyzer is a fully automated system for clinical chemistry analysis intended for the in vitro quantitative/qualitative determination of analytes in body fluids. Recall Number Z-0696-2013
REASON
A software security issue with Oracles TNS-Listener component has been identified. TNS-Listener is supplied with the Roche COBAS INTEGRA 400/400 plus Analyzers. The Oracle TNS-Listener can be considered as an authentication and redirection component between the client and the database inside the Roche product. This means an attacker could register their own non-Roche database via remote access over the network to the Roche product and read and write database queries without authentication and therefore modify the content of a database.
RECALLING FIRM/MANUFACTURER
Roche Diagnostics Operations, Inc., Indianapolis, IN 11/19/2012. Voluntary: Firm Initiated recall is ongoing.
VOLUME OF PRODUCT IN COMMERCE
845 units
DISTRIBUTION
Nationwide and Puerto Rico
___________________________________