#CMS8000
CISA is warning that Contec CMS8000 devices, a widely used healthcare patient monitoring device, include a backdoor that quietly sends patient data (China) IP address and downloads and executes files on the device.

www.bleepingcomputer.com/news/securit...
Backdoor found in two healthcare patient monitors, linked to IP in China
The US Cybersecurity and Infrastructure Security Agency (CISA) is warning that Contec CMS8000 devices, a widely used healthcare patient monitoring device, include a backdoor that quietly sends patient...
www.bleepingcomputer.com
January 31, 2025 at 8:17 AM
La Cybersecurity and Infrastructure Security Agency (CISA) degli Stati Uniti avverte che i dispositivi Contec CMS8000

un dispositivo ampiamente utilizzato per il monitoraggio dei pazienti nel settore sanitario ⬇️

www.bleepingcomputer.com/news/securit...
Backdoor found in two healthcare patient monitors, linked to IP in China
The US Cybersecurity and Infrastructure Security Agency (CISA) is warning that Contec CMS8000 devices, a widely used healthcare patient monitoring device, include a backdoor that quietly sends patient...
www.bleepingcomputer.com
January 31, 2025 at 2:19 PM
#Backdoor found in two #healthcare patient monitors, linked to #IP in #China

The #US #CISA is warning that #Contec #CMS8000 devices, include a backdoor that quietly sends patient data to a remote IP address and downloads and executes files on the device.

www.bleepingcomputer.com/news/securit...
Backdoor found in two healthcare patient monitors, linked to IP in China
The US Cybersecurity and Infrastructure Security Agency (CISA) is warning that Contec CMS8000 devices, a widely used healthcare patient monitoring device, include a backdoor that quietly sends patient...
www.bleepingcomputer.com
February 1, 2025 at 8:38 PM
Medizinische Überwachung:
Backdoor in verbreiteten Patientenmonitoren entdeckt

Durch die Backdoor fließen nicht nur laufend Patientendaten nach China. Auch lassen sich die Geräte von dort aus vollständig kontrollieren. Betroffen #Contec #CMS8000

www.golem.de/news/medizin...
Golem.de: IT-News für Profis
www.golem.de
February 1, 2025 at 9:59 AM
Contec CMS8000 patient monitors contain a hidden backdoor
Contec CMS8000 patient monitors contain a hidden backdoor
The U.S. CISA and the FDA warned of a hidden backdoor in Contec CMS8000 and Epsimed MN-120 patient monitors.
securityaffairs.com
February 1, 2025 at 1:16 AM
CISA and FDA Warn of Critical Backdoor in Contec CMS8000 Patient Monitors
CISA and FDA Warn of Critical Backdoor in Contec CMS8000 Patient Monitors
thehackernews.com
January 31, 2025 at 3:20 PM
The US Cybersecurity and Infrastructure Security Agency (CISA) is warning that Contec CMS8000 devices, a widely used healthcare patient monitoring device, include a backdoor that quietly sends patient data to a remote IP address and downloads and executes files on the device.
Backdoor found in two healthcare patient monitors, linked to IP in China
The US Cybersecurity and Infrastructure Security Agency (CISA) is warning that Contec CMS8000 devices, a widely used healthcare patient monitoring device, include a backdoor that quietly sends patient data to a remote IP address and downloads and executes files on the device.
www.bleepingcomputer.com
January 30, 2025 at 11:31 PM
Here more detailed information of #CISA about the #backdoor in #Contec #CMS8000

www.cisa.gov/sites/defaul...
www.cisa.gov
February 1, 2025 at 8:39 PM
#CISA is warning that Contec #CMS8000 devices, a widely used healthcare patient monitoring device, include a backdoor that quietly sends patient data to a remote IP address and downloads and executes files on the device. #China #backdoor www.bleepingcomputer.com/news/securit...
Backdoor found in two healthcare patient monitors, linked to IP in China
The US Cybersecurity and Infrastructure Security Agency (CISA) is warning that Contec CMS8000 devices, a widely used healthcare patient monitoring device, include a backdoor that quietly sends patient...
www.bleepingcomputer.com
January 31, 2025 at 7:58 PM
Uno dei primi contenuti su #RdF fu l'hack delle pompe di insulina.
Ricevetti un commento del genere "ma che caz*o se ne fanno di acherarti la siringa"

www.bleepingcomputer.com/news/securit...

💉
Backdoor found in two healthcare patient monitors, linked to IP in China
The US Cybersecurity and Infrastructure Security Agency (CISA) is warning that Contec CMS8000 devices, a widely used healthcare patient monitoring device, include a backdoor that quietly sends patient...
www.bleepingcomputer.com
January 31, 2025 at 6:21 AM
Le matériel de monitoring de patient Contec CMS8000 fabriqué en Chine envois les données à une adresse IP codée en dur.

Plus de détail dans le lien 👇

www.tomshardware.com/tech-industr...
Backdoor uncovered in China-made patient monitors — Contec CMS8000 raises questions about healthcare device security
US security agency reports that China-made hospital patient monitors contain a backdoor that sends confidential monitoring data to a third-party university.
www.tomshardware.com
February 2, 2025 at 6:26 PM
www.fda.gov/medical-devi... Patient monitors with malicious backdoors…CAZZO
Cybersecurity Vulnerabilities - Patient Monitors from Contec, Epsimed
The FDA is raising awareness about cybersecurity vulnerabilities with Contec CMS8000 and Epsimed MN-120 patient monitors.
www.fda.gov
January 31, 2025 at 7:40 PM
Todays #100daysofyara rule targets the CISA report for this Contec CMS8000 backdoor

Rule: github.com/mgreen27/100...
February 1, 2025 at 1:06 PM
🚨Team82 looked into the alleged backdoor in Contec CMS8000 patient monitors and concluded that may not be the case. Read more here: claroty.com/team82/resea... #healthcare #cybersecurity
Do the CONTEC CMS8000 Patient Monitors Contain a Chinese Backdoor? The Reality is More Complicated…
Team82 investigated what CISA labeled a backdoor in the Contec CMS8000 patient monitoring system and concluded that instead, the decision to include a hardcoded IP address is instead an insecure and r...
claroty.com
February 4, 2025 at 12:44 AM
Backdoor in hospital monitors.

I spent years unsuccessfully trying to get at raw monitoring data. Guess there was an easier way…

#MedSky #PedSky #NeoSky

1st source: www.bleepingcomputer.com/news/securit...

2nd source: www.cisa.gov/news-events/...
Backdoor found in two healthcare patient monitors, linked to IP in China
The US Cybersecurity and Infrastructure Security Agency (CISA) is warning that Contec CMS8000 devices, a widely used healthcare patient monitoring device, include a backdoor that quietly sends patient...
www.bleepingcomputer.com
January 31, 2025 at 10:11 AM
February 1, 2025 at 1:59 AM
We received information regarding a cybersecurity risk associated with the Contec CMS8000 monitor used for patient vital signs. Its remote access feature, if enabled, could be hacked, potentially exposing patient information and interfering with how vital signs are presented/monitored.

1 of 2
February 12, 2025 at 7:44 PM
not that it matters but knowing chinese devs it's always hard to tell whether it's a backdoor backdoor, or more are you telling me we aren't actually allowed to ship a shortcut patching mechanism that just allows us to do live modifications, and also keep a copy of all data to make support easier
Backdoor found in two healthcare patient monitors, linked to IP in China
The US Cybersecurity and Infrastructure Security Agency (CISA) is warning that Contec CMS8000 devices, a widely used healthcare patient monitoring device, include a backdoor that quietly sends patient...
www.bleepingcomputer.com
February 1, 2025 at 7:18 AM
Contec Health CMS8000 Patient Monitor | CISA www.cisa.gov/news-events/...
Contec Health CMS8000 Patient Monitor | CISA
www.cisa.gov
February 3, 2025 at 5:45 AM
#CMS8000 backdoor

Hardcoded IP: 202.114.4[.]119 (h/t @craiu.bsky.social) registered to Tsinghua University 👀

VT link:
www.virustotal.com/gui/file/4e4...

📝 www.cisa.gov/sites/defaul...
www.cisa.gov
January 31, 2025 at 9:28 PM
While I appreciate this disclosure and think it is important - I am not sure what a consumer is supposed to do with this?

“I’m sorry Doctor, I need you to hook me up to a different heart monitor. kthanksbye”

Via @jgreig.bsky.social & @therecordmedia.bsky.social
FDA, CISA warn of backdoor in popular patient monitor used by US hospitals
The Contec CMS8000, a patient monitor made by a company based in China, has vulnerabilities in its firmware that directly expose it to unauthorized access.
therecord.media
January 31, 2025 at 5:53 PM