CISA has found evidence of Contec CMS8000 and re-labelled Epsimed MN-120 devices beaconing to a public IP address
Summary
CISA has found evidence of Contec CMS8000 and re-labelled Epsimed MN-120 devices beaconing to a public IP address
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published a medical product advisory for the Contec Health CMS8000 Patient Monitor to address one critical and three high severity vulnerabilities. The Contec CMS8000 is a patient monitor used to display real-time information such as the vital signs of a patient, including temperature, heartbeat, and blood pressure. Additionally, the CMS8000 includes remote monitoring features, which use an internet connection to allow a healthcare provider to evaluate patient vital signs from another location.
CISA and the U.S. Food and Drug Administration (FDA) have advised that all versions of the CMS8000 firmware potentially contain a backdoor and are vulnerable to remote code execution (RCE).
Vulnerability details
Threat updates
Remediation advice
Affected organisations are strongly encouraged to review CISA advisory ICSMA-25-030-01 and follow the mitigations recommended below.
Any actions taken by affected organisations should be conducted in accordance with local risk tolerances and subjected to a local risk assessment.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 26 February 2025 11:33 am