CISA, FDA Issue Warning Over Backdoor in China’s Contec Patient Monitors

Contact Your Elected Officials
The Epoch Times Header

FDA recommended hospitals stop using the devices or disconnect them from the internet.

A patient monitor made by Chinese manufacturer Contec contains a backdoor that could allow an attacker to access patient data and remotely manipulate the devices, U.S. authorities said on Friday.

The Contec patient monitor CMS8000 is a device used to monitor human vital signs in hospitals and and clinics in the European Union and the United States.

The Food and Drug Administration (FDA) issued a statement, recommending hospitals and caregivers check Contec CMS8000 monitors, disconnect the device from the internet, or stop using it if the device relies on remote monitoring features.

The recommendation also applies to the same devices relabelled and sold as Epsimed MN-120 patient monitors.

“Once the patient monitor is connected to the internet, it begins gathering patient data, including personally identifiable information (PII) and protected health information (PHI), and exfiltrating (withdrawing) the data outside of the health care delivery environment,” the FDA said.

The device also contains a backdoor that can allow unauthorized persons to cause the device to crash or malfunction, or to corrupt data on the device, the FDA said.

The regulator said it’s not currently aware of any cybersecurity incidents, injuries, or deaths related to the vulnerabilities found on the device. It asked users to report any problems they find.

The vulnerabilities were identified by a research team from the Cybersecurity & Infrastructure Security Agency (CISA), which analyzed three versions of firmware for the Contec CMS8000 patient monitor.

The team found a backdoor that connects the devices to a hard-coded IP address, “allowing the device to download and execute unverified remote files,” CISA said in a report detailing the team’s findings.

The agency didn’t disclose the location of the IP address, stating only that it belongs to a “third-party university.”

The research team determined that it is “very unlikely” the backdoor serves as an alternative update mechanism due to the code’s “highly unusual characteristics,” which differ from those of other update mechanisms.

CISA said when the backdoor function on the device is executed, “files on the device are forcibly overwritten” without the knowledge of the end user, so hospitals won’t know what software is running on the device.

By Lily Zhou

Read Full Article on TheEpochTimes.com

The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

The Woke Left Goes Lock, Stock And Cracker Barrel

Another legendary American institution has been targeted by woke leftists. This time it is the popular family restaurant chain, Cracker Barrel, founded in 1969.

‘Indigenous Drag Story Hour’: A Back-to-Public-School Treat For the Kids

I gave leading child-grooming outfit Drag Queen Story Hour my email to solicit me for funds to convert more public school kids into trannies.

Is Trump’s Throw Down Going Down?

During a recent announcement at the White House, President Trump, and other participants appeared without ties and with there top shirt buttons undone.

Defying Mr. Softee

Revived after decades of decline, the Presidential Physical Fitness Test returns as a merit-based antidote to rising childhood obesity and chronic disease.

DOJ Releases Maxwell Proffer Transcript: CASE CLOSED?

DOJ released transcript and audio recordings of Ghislaine Maxwell’s proffer — an image-laundering operation to get herself a pardon for sex-trafficking crimes.

Federal Judge Blocks Texas Law on Ten Commandments in Classrooms

Court in Texas issued preliminary injunction temporarily blocking new state law that would have required public school classrooms to display the Ten Commandments.

Interpol-Led Operation Leads to Arrests of More Than 1,200 Suspected Cybercriminals in Africa

A sweeping intergovernmental operation coordinated by Interpol resulted in arrests of 1,209 alleged cybercriminals across Africa and takedown of 11,432 malicious infrastructures.

California Moves Forward on Redistricting in Retaliation Against Texas

California signed an order to redraw its election boundaries to favor Democrats in a retaliatory act, ahead of a Texas Republican effort to do the same.

Truck Driver Accused by Trump Administration of Being in the US Illegally Is Denied Bond

A illegal alien truck driver accused of making an illegal U-turn that killed three people in Florida last week was denied bond Saturday.

Trump Warns He May Send Troops to Baltimore to Fight Crime

President Trump suggested he’s contemplating sending National Guard troops to Baltimore, Maryland, to fight “crime disaster” in the city.

Trump’s Tariffs Will Reduce Deficits by $4 Trillion Over Next Decade, Says CBO Report

A report released by the CBO predicted that President Donald Trump’s tariffs will reduce federal deficits by around $4 trillion over the next decade.

USDA Issues Memorandum Prioritizing American Energy on National Forest Lands

Secretary Rollins said that the United States will no longer allow foreign-made solar panels or inefficient energy projects to undermine national security.

US Pauses Visas for Commercial Truck Drivers, Citing Safety and Other Impacts

The Trump administration will immediately pause the issuance of all worker visas for commercial truck drivers, Sec of State Marco Rubio said.
spot_img

Related Articles