CISA, FDA Issue Warning Over Backdoor in China’s Contec Patient Monitors

The Epoch Times Header

FDA recommended hospitals stop using the devices or disconnect them from the internet.

A patient monitor made by Chinese manufacturer Contec contains a backdoor that could allow an attacker to access patient data and remotely manipulate the devices, U.S. authorities said on Friday.

The Contec patient monitor CMS8000 is a device used to monitor human vital signs in hospitals and and clinics in the European Union and the United States.

The Food and Drug Administration (FDA) issued a statement, recommending hospitals and caregivers check Contec CMS8000 monitors, disconnect the device from the internet, or stop using it if the device relies on remote monitoring features.

The recommendation also applies to the same devices relabelled and sold as Epsimed MN-120 patient monitors.

“Once the patient monitor is connected to the internet, it begins gathering patient data, including personally identifiable information (PII) and protected health information (PHI), and exfiltrating (withdrawing) the data outside of the health care delivery environment,” the FDA said.

The device also contains a backdoor that can allow unauthorized persons to cause the device to crash or malfunction, or to corrupt data on the device, the FDA said.

The regulator said it’s not currently aware of any cybersecurity incidents, injuries, or deaths related to the vulnerabilities found on the device. It asked users to report any problems they find.

The vulnerabilities were identified by a research team from the Cybersecurity & Infrastructure Security Agency (CISA), which analyzed three versions of firmware for the Contec CMS8000 patient monitor.

The team found a backdoor that connects the devices to a hard-coded IP address, “allowing the device to download and execute unverified remote files,” CISA said in a report detailing the team’s findings.

The agency didn’t disclose the location of the IP address, stating only that it belongs to a “third-party university.”

The research team determined that it is “very unlikely” the backdoor serves as an alternative update mechanism due to the code’s “highly unusual characteristics,” which differ from those of other update mechanisms.

CISA said when the backdoor function on the device is executed, “files on the device are forcibly overwritten” without the knowledge of the end user, so hospitals won’t know what software is running on the device.

By Lily Zhou

Read Full Article on TheEpochTimes.com

The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

Columns

More Proof, the Democratic Party is Imploding!

Jason Pizzo, the leading Democrat in the Florida Senate announced his departure from the Democratic Party saying he sees the party as dead in Florida.

American Psychiatric Association vs. MAHA: Shots Fired

When Trump formed the MAHA Commission, the parameters were so reasonable that it was hard to imagine how the biomedical establishment could object.

Evaluating Foreign Affairs’ Warning About The Risks Of An Emboldened & Remilitarized Germany

Foreign Affairs warned earlier this month that an emboldened...

9 Things to Know About UK Supreme Court Ruling on Sex, Gender

Britain’s highest court has ruled that the words “woman” and “sex” refer to “a biological woman and biological sex,” in a landmark decision.

Chinese Exporters Begin to Feel Pain of Tariffs as Containers Stack Up

China’s exporters are scrambling to find domestic buyers for their consumer goods as orders from the U.S. have dried up during an escalating trade war.

News

Court Ruling Limits Ozempic Copies in Favor of FDA, Novo Nordisk

Federal court ruled against trade group representing compounding pharmacies, siding with FDA and Novo Nordisk in dispute over copies of Ozempic and Wegovy.

Judge Blocks Removal of Potential Deportees From Texas District

Federal judge temporarily restrained Trump admin from removing individuals from Southern District of Texas in attempt to deport Venezuelan gang members under the Alien Enemies Act.

Former Rep. George Santos Sentenced to More Than 7 Years in Prison

Former Rep. George Santos (R-N.Y.) was sentenced on April 25 to more than 7 years in federal prison on wire fraud and aggravated identity theft charges.

Dozens of House Democrats Seek Answers on DOGE Report

House Dems sent letter to Trump admin seeking answers regarding “whistleblower report” from federal labor board staffer with allegations against DOGE.

FBI Arrests Wisconsin Judge Hannah Dugan Over Obstructing, Kash Patel Says

FBI arrested a Milwaukee County, Wisconsin, circuit judge for allegedly assisting an illegal immigrant in evading arrest, FBI Director Kash Patel said.

Former New Mexico Judge, Wife Arrested Over Alleged Evidence Tampering

Inmate bookingreports released by Doña Ana County Detention Center show Judge Cano and his wife were arrested for evidence tampering.

Judge Blocks Trump Admin Effort to Remove DEI From Public Schools

Before deadline for states to certify DEI programs have ended in public schools, a federal court halted Trump admin’s requirement, siding with NEA teachers’ union.

Trump’s Agenda Faces Pushback Amid Legal Battles

Trump faces onslaught of challenges to his agenda, some reaching the nation’s highest court and could ultimately shape US legal landscape.
spot_img

Related Articles