CISA, FDA Issue Warning Over Backdoor in China’s Contec Patient Monitors

Contact Your Elected Officials
The Epoch Times Header

FDA recommended hospitals stop using the devices or disconnect them from the internet.

A patient monitor made by Chinese manufacturer Contec contains a backdoor that could allow an attacker to access patient data and remotely manipulate the devices, U.S. authorities said on Friday.

The Contec patient monitor CMS8000 is a device used to monitor human vital signs in hospitals and and clinics in the European Union and the United States.

The Food and Drug Administration (FDA) issued a statement, recommending hospitals and caregivers check Contec CMS8000 monitors, disconnect the device from the internet, or stop using it if the device relies on remote monitoring features.

The recommendation also applies to the same devices relabelled and sold as Epsimed MN-120 patient monitors.

“Once the patient monitor is connected to the internet, it begins gathering patient data, including personally identifiable information (PII) and protected health information (PHI), and exfiltrating (withdrawing) the data outside of the health care delivery environment,” the FDA said.

The device also contains a backdoor that can allow unauthorized persons to cause the device to crash or malfunction, or to corrupt data on the device, the FDA said.

The regulator said it’s not currently aware of any cybersecurity incidents, injuries, or deaths related to the vulnerabilities found on the device. It asked users to report any problems they find.

The vulnerabilities were identified by a research team from the Cybersecurity & Infrastructure Security Agency (CISA), which analyzed three versions of firmware for the Contec CMS8000 patient monitor.

The team found a backdoor that connects the devices to a hard-coded IP address, “allowing the device to download and execute unverified remote files,” CISA said in a report detailing the team’s findings.

The agency didn’t disclose the location of the IP address, stating only that it belongs to a “third-party university.”

The research team determined that it is “very unlikely” the backdoor serves as an alternative update mechanism due to the code’s “highly unusual characteristics,” which differ from those of other update mechanisms.

CISA said when the backdoor function on the device is executed, “files on the device are forcibly overwritten” without the knowledge of the end user, so hospitals won’t know what software is running on the device.

By Lily Zhou

Read Full Article on TheEpochTimes.com

The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

James Franklin’s contract fallout

Penn State’s decision to fire head coach James Franklin after a disappointing 22–21 home loss to Northwestern will cost an estimated $56 million buyout. 

Trump’s Middle East Trip Led to Historic Breakthroughs

Trump’s bold, unconventional strategy helped end the Israel-Hamas war and set the stage for a more stable, prosperous Middle East.

Pretending Really Hard

The world is real and so are its problems, too. Reality is the enemy of liberals, even though they are pretending, really hard, that it is not.

Trump 2.0’s Eurasian Balancing Act Has Failed

Trump's Eurasian balancing act has failed due to his arrogant and aggressive approach towards all three countries.

Should Palestinian clans rebelling against Hamas be given Gaza?

Hamas’s October 7 attack exposed its violent ideology, showing cruelty toward its enemies and also against the Palestinian people it claims to defend.

Trump, Patel Confirm FBI Special Agents Will Get Paid During Shutdown

FBI special agents will receive their paychecks despite the government shutdown, according to President Donald Trump and FBI Director Kash Patel.

Trump Admin Withholds $41 Million From California Over English-Language Trucking Rules

Trump admin withholds $40.6M in California transportation funds, citing failure to meet federal English proficiency rules for truck drivers.

An Inconvenient Study – Feature Film

Journalist Del Bigtree challenged a top infectious disease expert in 2016 to a vaxxed vs. unvaxxed study. The long-hidden results are finally revealed.

Federal Judge Temporarily Blocks Trump Admin’s Shutdown-Related Layoffs

A federal judge on Oct. 15 temporarily blocked President Donald Trump’s plan to lay off certain federal employees during the government shutdown. 

Trump Posthumously Awards Charlie Kirk the Presidential Medal of Freedom

President Trump posthumously awarded Charlie Kirk the Presidential Medal of Freedom in the White House Rose Garden on Oct 14, Charlie's birthday.

Trump Names Longtime Adviser Dan Scavino to Key Personnel Position

One of President Trump’s longtime advisers, Dan Scavino, is going to be in charge of selecting and appointing key positions within the executive branch.

First Lady’s Effort Helped Reunite 8 War-Displaced Children With Their Families

First lady Melania Trump said 8 children impacted by the fighting between Ukraine and Russia were reunited with their families on Oct. 9.

Trump to Impose New 100 Percent Tariff on China on Nov. 1

President Trump said that the US will impose an additional 100 percent tariffs on Chinese goods and export controls on critical software starting on Nov. 1.
spot_img

Related Articles

Popular Categories

MAGA Business Central