CISA, FDA Issue Warning Over Backdoor in China’s Contec Patient Monitors

5Mind. The Meme Platform
The Epoch Times Header

FDA recommended hospitals stop using the devices or disconnect them from the internet.

A patient monitor made by Chinese manufacturer Contec contains a backdoor that could allow an attacker to access patient data and remotely manipulate the devices, U.S. authorities said on Friday.

The Contec patient monitor CMS8000 is a device used to monitor human vital signs in hospitals and and clinics in the European Union and the United States.

The Food and Drug Administration (FDA) issued a statement, recommending hospitals and caregivers check Contec CMS8000 monitors, disconnect the device from the internet, or stop using it if the device relies on remote monitoring features.

The recommendation also applies to the same devices relabelled and sold as Epsimed MN-120 patient monitors.

“Once the patient monitor is connected to the internet, it begins gathering patient data, including personally identifiable information (PII) and protected health information (PHI), and exfiltrating (withdrawing) the data outside of the health care delivery environment,” the FDA said.

The device also contains a backdoor that can allow unauthorized persons to cause the device to crash or malfunction, or to corrupt data on the device, the FDA said.

The regulator said it’s not currently aware of any cybersecurity incidents, injuries, or deaths related to the vulnerabilities found on the device. It asked users to report any problems they find.

The vulnerabilities were identified by a research team from the Cybersecurity & Infrastructure Security Agency (CISA), which analyzed three versions of firmware for the Contec CMS8000 patient monitor.

The team found a backdoor that connects the devices to a hard-coded IP address, “allowing the device to download and execute unverified remote files,” CISA said in a report detailing the team’s findings.

The agency didn’t disclose the location of the IP address, stating only that it belongs to a “third-party university.”

The research team determined that it is “very unlikely” the backdoor serves as an alternative update mechanism due to the code’s “highly unusual characteristics,” which differ from those of other update mechanisms.

CISA said when the backdoor function on the device is executed, “files on the device are forcibly overwritten” without the knowledge of the end user, so hospitals won’t know what software is running on the device.

By Lily Zhou

Read Full Article on TheEpochTimes.com

Contact Your Elected Officials
The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

Gates Discussed Pandemic with Epstein in 2017!?

An email, from the newly released Epstein files, sent to Epstein with the subject “Preparing for Pandemics" allegedly came from Bill Gates.

Public Health™ Fatties For Flu Shots!

Meet Sarah Hoffman, former Alberta Minister of Health — in any sane time and place, the unlikeliest of sources for sound Public Health™ counsel.

How Will Key Countries Respond To The US’ Attempted Restoration Of Unipolarity?

The US’ new National Security and Defense Strategies outline the “Trump Doctrine,” signaling a grand strategy to restore American unipolar dominance worldwide.

The Federal Courts Have Become Another Political Branch

Politics has increasingly contaminated institutions once expected to stand apart from partisan struggle—including the judiciary.

“Melania” Movie Beats Negative Pre-Hype

My wife and I went to see the “Melania”...

Deputy AG Suggests Organized Group Is Behind Minneapolis Protests

Deputy Attorney General Todd Blanche suggested on Feb. 2 that an organized group is behind the protests in Minnesota.

RFK Jr. Announces $100 Million Program Aimed at Homelessness and Addiction

Health Secretary Robert F. Kennedy Jr. announced a new $100 million program that he said will help homeless people find jobs and treat drug abuse.

Trump Says Administration Will Seek $1 Billion in Damages From Harvard

Trump alleged that Harvard University had engaged in criminal...

Catholic Network Files Suit Against Trump Admin Over Immigrant Visa Pause

The Trump administration halted visas to people from 75 nations last month due to the risk of immigrants becoming dependent on government welfare.

Trump, Colombia’s Petro to Meet for White House Talks After Months of Sharp Tension

President Donald Trump will welcome Colombian President Gustavo Petro for a bilateral discussion at the White House in Washington on Feb. 3.

Trump Says UN Still Has Tremendous Potential, as Organization Struggles Financially

President Trump denied claims the UN may close its NYC headquarters for financial reasons, while praising the organization’s “tremendous potential.”

Trump Launches $12 Billion ‘Project Vault’ Critical Minerals Stockpile

President Donald Trump announced on Feb. 2 a new strategic private sector critical minerals stockpile.

US, India to Slash Tariffs Under New Trade Deal, Trump Says

The US and India have reached a trade agreement and will begin lowering tariffs on each other’s goods immediately, Trump announced
spot_img

Related Articles