HC3 seeks removal of critical OpenSSL cybersecurity vulnerability patching in healthcare
HC3 said organisations should immediately resolve and prioritise patching OpenSSL's critical cybersecurity vulnerability, which will be received on November 1 and should be prioritised upon release.

The alert explained, "OpenSSL is an open-source cryptographic library utilised by common operating systems. It implements Transport Layer Security, and Secure Sockets Layer is implemented by its predecessor protocol for securing the web and other Internet-facing servers’ communication.
Vulnerability's negative consequences
HC3 noted that since the vulnerability is pertinent across the private and public healthcare sectors, it can cause exploitation on a vast scale. The fact states that due to the vulnerability’s apparent egregious nature, immediate patching is essential after the release update on November 1.HC3 noted, "to understand the vulnerability’s technical details upon release, threat actors, both cyber criminals and state-sponsored, often reverse engineer a patch to develop an exploit. Thus, HC3 proposes that all health organisations treat this vulnerability as the highest priority."
FAQs:
- How critical is the vulnerability?
The criticality of the vulnerability is not yet known, but HC3 comments that "for OpenSSL, it is very uncommon to categorize a vulnerability as critical." - When is the issue classified as critical?
According to the OpenSSL website, the issue of the vulnerability is categorised as "critical" if it is likely to be exploited broadly and impacts standard configurations.
The Economic Times Business News App for the Latest News in Business, Sensex, Stock Market Updates & More.
The Economic Times News App for Quarterly Results, Latest News in ITR, Business, Share Market, Live Sensex News & More.