CISA, FDA Issue Warning Over Backdoor in China’s Contec Patient Monitors

5Mind. The Meme Platform
The Epoch Times Header

FDA recommended hospitals stop using the devices or disconnect them from the internet.

A patient monitor made by Chinese manufacturer Contec contains a backdoor that could allow an attacker to access patient data and remotely manipulate the devices, U.S. authorities said on Friday.

The Contec patient monitor CMS8000 is a device used to monitor human vital signs in hospitals and and clinics in the European Union and the United States.

The Food and Drug Administration (FDA) issued a statement, recommending hospitals and caregivers check Contec CMS8000 monitors, disconnect the device from the internet, or stop using it if the device relies on remote monitoring features.

The recommendation also applies to the same devices relabelled and sold as Epsimed MN-120 patient monitors.

“Once the patient monitor is connected to the internet, it begins gathering patient data, including personally identifiable information (PII) and protected health information (PHI), and exfiltrating (withdrawing) the data outside of the health care delivery environment,” the FDA said.

The device also contains a backdoor that can allow unauthorized persons to cause the device to crash or malfunction, or to corrupt data on the device, the FDA said.

The regulator said it’s not currently aware of any cybersecurity incidents, injuries, or deaths related to the vulnerabilities found on the device. It asked users to report any problems they find.

The vulnerabilities were identified by a research team from the Cybersecurity & Infrastructure Security Agency (CISA), which analyzed three versions of firmware for the Contec CMS8000 patient monitor.

The team found a backdoor that connects the devices to a hard-coded IP address, “allowing the device to download and execute unverified remote files,” CISA said in a report detailing the team’s findings.

The agency didn’t disclose the location of the IP address, stating only that it belongs to a “third-party university.”

The research team determined that it is “very unlikely” the backdoor serves as an alternative update mechanism due to the code’s “highly unusual characteristics,” which differ from those of other update mechanisms.

CISA said when the backdoor function on the device is executed, “files on the device are forcibly overwritten” without the knowledge of the end user, so hospitals won’t know what software is running on the device.

By Lily Zhou

Read Full Article on TheEpochTimes.com

Contact Your Elected Officials
The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

The Epstein Mystery Takes A New Turn

This Epstein case is now the story with unending questions. However, the first question that needs to be answered is “Who killed Jeffrey Epstein?”

Istvan Kapitany Might Succeed In Hungary Where George Soros Failed

The Third Gulf War has been raging for almost...
00:00:30

Fresh bite on a vintage motto

Whether aimed at politicians, corporations, or the grocery aisle, “Where’s the beef?” is a demand for substance, fairness, and honesty.

Trump’s Anger with NATO is Justified!

President Trump has been critical about NATO and their unwillingness to take responsibility for their own defense, including at the Strait of Hormuz.
00:01:04

Glenn Beck Delivers Wakeup Call Tonight!

Some conservative podcasters seem to have gone on the Deep State payroll, have been infected with TDS, and/or see the government of Israel as our enemy.

HHS Confirms New Investment in Cancer Vaccines

U.S. health agencies are investing in vaccines that are aimed at preventing cancer from returning, officials said March 22.

Sheriff Investigating Nancy Guthrie Disappearance Says Case Hasn’t Gone Cold

Speaking to Tucson’s Arizona Daily Star on March 20, Pima County Sheriff Chris Nanos said the Guthrie case is “not even close” to having gone cold.

Judge Halts Development Meeting for Muslim City in Texas

Texas judge temporarily blocked a utility district meeting tied to development of a proposed Muslim enclave known as EPIC City, also called The Meadow.

2 Pilots Killed in LaGuardia Airport Runway Collision

Two pilots were killed when an Air Canada Express regional jet collided with a fire truck while landing at New York’s LaGuardia Airport on March 22.
00:27:39

US Looking to Seize Iranian Defectors’ Money: Bessent

Treasury Sec. Scott Bessent said that the US is moving to seize funds transferred abroad by Iranian defectors, so it can be to returned to the Iranian people.

Trump Says He’s ‘Not Putting Troops Anywhere’ Amid Iran War

President Donald Trump met with Japanese Prime Minister Sanae Takaichi to discuss the Iran war, saying he is not inclined to send U.S. ground troops.

US Agencies Terminated or Reduced 95 Wasteful Contracts Worth $2 Billion: DOGE

Federal agencies canceled or scaled back 95 wasteful contracts worth up to $2B in the last four weeks, saving taxpayers $757M.
00:01:01

Trump Expects Iran War to End ‘Soon’

President Trump said on March 16 that he believes the U.S.–Israeli war with Iran could be “wrapped up soon,” but its unlikely to end within the week.
spot_img

Related Articles

Popular Categories

MAGA Business Central