CISA, FDA Issue Warning Over Backdoor in China’s Contec Patient Monitors

Contact Your Elected Officials
The Epoch Times Header

FDA recommended hospitals stop using the devices or disconnect them from the internet.

A patient monitor made by Chinese manufacturer Contec contains a backdoor that could allow an attacker to access patient data and remotely manipulate the devices, U.S. authorities said on Friday.

The Contec patient monitor CMS8000 is a device used to monitor human vital signs in hospitals and and clinics in the European Union and the United States.

The Food and Drug Administration (FDA) issued a statement, recommending hospitals and caregivers check Contec CMS8000 monitors, disconnect the device from the internet, or stop using it if the device relies on remote monitoring features.

The recommendation also applies to the same devices relabelled and sold as Epsimed MN-120 patient monitors.

“Once the patient monitor is connected to the internet, it begins gathering patient data, including personally identifiable information (PII) and protected health information (PHI), and exfiltrating (withdrawing) the data outside of the health care delivery environment,” the FDA said.

The device also contains a backdoor that can allow unauthorized persons to cause the device to crash or malfunction, or to corrupt data on the device, the FDA said.

The regulator said it’s not currently aware of any cybersecurity incidents, injuries, or deaths related to the vulnerabilities found on the device. It asked users to report any problems they find.

The vulnerabilities were identified by a research team from the Cybersecurity & Infrastructure Security Agency (CISA), which analyzed three versions of firmware for the Contec CMS8000 patient monitor.

The team found a backdoor that connects the devices to a hard-coded IP address, “allowing the device to download and execute unverified remote files,” CISA said in a report detailing the team’s findings.

The agency didn’t disclose the location of the IP address, stating only that it belongs to a “third-party university.”

The research team determined that it is “very unlikely” the backdoor serves as an alternative update mechanism due to the code’s “highly unusual characteristics,” which differ from those of other update mechanisms.

CISA said when the backdoor function on the device is executed, “files on the device are forcibly overwritten” without the knowledge of the end user, so hospitals won’t know what software is running on the device.

By Lily Zhou

Read Full Article on TheEpochTimes.com

The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

Rise by the Conspiracy Theory, Fall by the Conspiracy Theory

The uproar in the MAGA world over the failure to release the Jeffrey Epstein client list should be a cause for serious concern for President Trump.

Liberal Democrat Content Creators are Despicable Defamationers

What should Christian conservatives do when confronted with false information to the point of bearing false witness against someone like President Trump?

Ben Shapiro Warning Me Not to Listen to InfoWars Makes Me Want to Listen 10x Harder

This rant from Ben Shapiro reveals more about him and his low opinion of his audience to whom he peddles his slop than it does about its target, Alex Jones.

Epstein’s Aftermath: Planes, Blames, and Autocrats

There are so many real, honest great journalists reporting the news on the internet these days that some really good content gets overlooked.

Why the Trump Administration is Sitting on the Epstein Files

President Trump, AG Bondi, and FBI Dir. Patel have the advantage over us in that they see the big overall picture when it comes to the Epstein List.

Justice Department Requests Data on Criminal Illegal Immigrants in California Jails

DOJ requested data on incarcerated illegal immigrants from sheriffs in CA counties, including reasons for arrests or convictions and scheduled release dates.

Columbia University Announces Commitment to Combating Anti-Semitism

Columbia University will put in place several measures to fight anti-Semitism on its campuses, the institution’s acting president, Claire Shipman, said.

America’s Biggest Medical Facility for Transgender Youth Is Shutting Down

Children’s Hospital Los Angeles, the nation’s largest provider of gender procedures for youth identifying as transgender will shut down its program.

More Than 1 Million Illegal Immigrants Have Self-Deported, Says Senior White House Official

More than 1 million illegal immigrants have self-deported since President Donald Trump took office according to Stephen Miller.

What’s Behind the US–Canada Lumber Feud?

Industry group, U.S. Lumber Coalition, argues that Canada’s wood products, which receive government subsidies, are sold at an artificially low price.

Trump Undergoes Medical Exam After Swelling in Legs

President Trump underwent a medical evaluation after swelling in his lower legs and bruising on his hands but is in good health, according to physician.

Top HHS Nominee Opposes Transgender Treatments for Children

President Trump’s nominee for a top post at HHS told senators he opposes giving drugs such as puberty blockers to children experiencing gender dysphoria.

Trump Says US Very Close to Trade Agreement With India, EU Deal Possible

President Trump said that the United States is “very close” to reaching a trade agreement with India, adding that a deal with EU is also possible.
spot_img

Related Articles