CISA, FDA Issue Warning Over Backdoor in China’s Contec Patient Monitors

Contact Your Elected Officials
The Epoch Times Header

FDA recommended hospitals stop using the devices or disconnect them from the internet.

A patient monitor made by Chinese manufacturer Contec contains a backdoor that could allow an attacker to access patient data and remotely manipulate the devices, U.S. authorities said on Friday.

The Contec patient monitor CMS8000 is a device used to monitor human vital signs in hospitals and and clinics in the European Union and the United States.

The Food and Drug Administration (FDA) issued a statement, recommending hospitals and caregivers check Contec CMS8000 monitors, disconnect the device from the internet, or stop using it if the device relies on remote monitoring features.

The recommendation also applies to the same devices relabelled and sold as Epsimed MN-120 patient monitors.

“Once the patient monitor is connected to the internet, it begins gathering patient data, including personally identifiable information (PII) and protected health information (PHI), and exfiltrating (withdrawing) the data outside of the health care delivery environment,” the FDA said.

The device also contains a backdoor that can allow unauthorized persons to cause the device to crash or malfunction, or to corrupt data on the device, the FDA said.

The regulator said it’s not currently aware of any cybersecurity incidents, injuries, or deaths related to the vulnerabilities found on the device. It asked users to report any problems they find.

The vulnerabilities were identified by a research team from the Cybersecurity & Infrastructure Security Agency (CISA), which analyzed three versions of firmware for the Contec CMS8000 patient monitor.

The team found a backdoor that connects the devices to a hard-coded IP address, “allowing the device to download and execute unverified remote files,” CISA said in a report detailing the team’s findings.

The agency didn’t disclose the location of the IP address, stating only that it belongs to a “third-party university.”

The research team determined that it is “very unlikely” the backdoor serves as an alternative update mechanism due to the code’s “highly unusual characteristics,” which differ from those of other update mechanisms.

CISA said when the backdoor function on the device is executed, “files on the device are forcibly overwritten” without the knowledge of the end user, so hospitals won’t know what software is running on the device.

By Lily Zhou

Read Full Article on TheEpochTimes.com

The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

Why Democracy, not Caesar, is the answer to our problems

Caesar-style leadership wins quick public support but inevitably sparks passionate resistance, conflict, bloodshed, and lasting social destabilization.

WATCH: Barack Obama Foments Color Revolutions in Eastern Europe

Obama astroturfed “pro-democracy” movements in Poland and Hungary to pressure their govts into accepting mass migration and social engineering.

J.B. Pritzker Puts the ILLeagals in ILLinois

Illinois Gov. J.B. Pritzker, once a California native, has revived the old “ILL” abbreviation—this time in his promotion of ILLegal aliens.

James Franklin’s contract fallout

Penn State’s decision to fire head coach James Franklin after a disappointing 22–21 home loss to Northwestern will cost an estimated $56 million buyout. 

Trump’s Middle East Trip Led to Historic Breakthroughs

Trump’s bold, unconventional strategy helped end the Israel-Hamas war and set the stage for a more stable, prosperous Middle East.

Trump Commutes Sentence of Former Rep. George Santos

President Trump commuted ex-Rep. George Santos’s seven-year prison sentence for fraud and identity theft, ordering his immediate release.

Jack Smith Referred to DOJ for Misconduct Investigation and Possible Disbarment

Former special counsel Jack Smith was criminally referred to the DOJ by Republican lawmakers for alleged misconduct and possible disbarment.

AI Is a ‘Real and Mysterious Creature,’ Not a Predictable Machine, Anthropic Co-Founder Warns

Handling AI is like dealing with “a real and mysterious creature, not a predictable machine,” said Jack Clark, co-founder of Anthropic, at a Berkeley conference.

Trump Refiles $15 Billion Defamation Lawsuit Against New York Times After Court Dismissal

Trump refiled his $15 billion defamation lawsuit against The New York Times, Penguin Random House, and 3 reporters after judge dismissed the case.

Army Corps of Engineers to Pause $11 Billion in Projects During Shutdown: Vought

Russ Vought, director of the White House’s OMB, has added to the growing pile of federal projects paused during the government shutdown.

Trump Signs Executive Order Putting New Restrictions on Federal Hiring

Trump signed an executive order directing federal agencies to restrict hiring, with exceptions for immigration, security, and political appointees.

Trump Says He Has Authorized Covert CIA Operations in Venezuela

President Trump authorized covert CIA operations in Venezuela, expanding U.S. assets there to increase pressure on President Nicolás Maduro’s regime.

Trump Posthumously Awards Charlie Kirk the Presidential Medal of Freedom

President Trump posthumously awarded Charlie Kirk the Presidential Medal of Freedom in the White House Rose Garden on Oct 14, Charlie's birthday.
spot_img

Related Articles

Popular Categories

MAGA Business Central