Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Waymo temporarily suspends service in San Francisco as robotaxis stall due to power outage

Electrical startups raise concerns as EU wateres down 2035 EV targets

Famous Israeli VC John Medved, who was diagnosed with ALS, championed technology to improve his life.

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » CISA and FDA warn the important backdoor of the Contec CMS8000 patient monitor
Identity

CISA and FDA warn the important backdoor of the Contec CMS8000 patient monitor

userBy userJanuary 31, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

LingeringJanuary 31, 2025LingeringRavy LakshmananVulnerability /Healthcare

Contech's important backdoor

The US Cyber ​​Security and Infrastructure Security Bureau (CISA) and the Food Pharmaceutical Bureau (FDA) have issued alerts on the existence of a CMS 8000 patient monitor and the Epsimed MN-20 patient monitor.

The vulnerability tracked as the CVE-2025-0626 is equipped with a CVSS V4 score 7.7 on a 10.0 scale. The flaws were reported to CISA by anonymous external researchers, along with the other two issues.

“The affected product will bypass the existing device network settings and send a remote access request to the hard -coded IP address,” CISA said in advisory. “This functions as a backdoor so that malicious actors can upload and overwrite files on the device.”

Cyber ​​security

“The reverse backdoor provides automatic connection from the Contec CMS8000 device to the hard -coded IP address so that the device can download and execute unidentified remote files. But a third -party university.”

The other two other identified vulnerabilities in the device are listed below-

CVE-2024-12248 (CVSS V4 Score: 9.3) -Arstable vulnerabilities that allow the attacker to send a specially formatted UDP request, describe any data, and execute a remote code execution CVE-2025-0683 (CVSS V4 Score : 8.2) – Privacy leak vulnerabilities that send the patient data of plain text to the hard -coded public IP address when the patient is attached to the monitor

With the success of the exploitation of CVE-2025-0683, devices with that indefinite IP address can access confidential patient information or open a door to the intermediate (AITM) scenario.

Security hole affects the following products-

CMS8000 Patient Monitor: Farm Wear version SMART3250-2.1.1.1.7.crams8000 Patient version CMS7.820.075.08 (0.75) CMS8000 Patient Monitor: Farmware version 7.820.120.01/0.93 (0.9) CMS8000 Patient monitor: All versions (CVE-2025-0626 and CVE-2025-0683)

Cyber ​​security

“These cyber security vulnerabilities allow unaccepted actors to bypass cyber security control, acquire access to devices, and operate them potentially,” FDA said, “said FDA. “Cyber ​​security vulnerabilities or deaths or deaths related to these cyber security vulnerabilities.

Given that these vulnerabilities are still, CISA recommends that the organization removes and deletes the Contec CMS8000 device from the network. It is worth noting that the device is also re-labeled and sold under the name MN-120.

It is also advised to check the monitor of the patient on signs of abnormal functions, such as “a contradiction between the vitals of the displayed patient and the patient’s actual physical condition.”

The CMS8000 patient monitor is manufactured by Contec Medical Systems, a developer of medical devices in Qinhuangdao in China. The website claims that the product has already been approved for FDA and is distributed to more than 130 countries and regions.

Did you find this article interesting? Follow on Twitter and Linkedin and read the exclusive content to post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleThe Arctic groundwater pumps harmful carbon into the sea.
Next Article The TechCrunch Cyber Glossary | TechCrunch
user
  • Website

Related Posts

Iran’s Infy APT resurfaces with new malware activity after years of silence

December 21, 2025

US Department of Justice charges $54 for ATM jackpotting scheme using Ploutus malware

December 20, 2025

Russian-linked hackers use Microsoft 365 device code phishing to take over accounts

December 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Waymo temporarily suspends service in San Francisco as robotaxis stall due to power outage

Electrical startups raise concerns as EU wateres down 2035 EV targets

Famous Israeli VC John Medved, who was diagnosed with ALS, championed technology to improve his life.

Iran’s Infy APT resurfaces with new malware activity after years of silence

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.