CISA, FDA Issue Warning Over Backdoor in China’s Contec Patient Monitors

5Mind. The Meme Platform
The Epoch Times Header

FDA recommended hospitals stop using the devices or disconnect them from the internet.

A patient monitor made by Chinese manufacturer Contec contains a backdoor that could allow an attacker to access patient data and remotely manipulate the devices, U.S. authorities said on Friday.

The Contec patient monitor CMS8000 is a device used to monitor human vital signs in hospitals and and clinics in the European Union and the United States.

The Food and Drug Administration (FDA) issued a statement, recommending hospitals and caregivers check Contec CMS8000 monitors, disconnect the device from the internet, or stop using it if the device relies on remote monitoring features.

The recommendation also applies to the same devices relabelled and sold as Epsimed MN-120 patient monitors.

“Once the patient monitor is connected to the internet, it begins gathering patient data, including personally identifiable information (PII) and protected health information (PHI), and exfiltrating (withdrawing) the data outside of the health care delivery environment,” the FDA said.

The device also contains a backdoor that can allow unauthorized persons to cause the device to crash or malfunction, or to corrupt data on the device, the FDA said.

The regulator said it’s not currently aware of any cybersecurity incidents, injuries, or deaths related to the vulnerabilities found on the device. It asked users to report any problems they find.

The vulnerabilities were identified by a research team from the Cybersecurity & Infrastructure Security Agency (CISA), which analyzed three versions of firmware for the Contec CMS8000 patient monitor.

The team found a backdoor that connects the devices to a hard-coded IP address, “allowing the device to download and execute unverified remote files,” CISA said in a report detailing the team’s findings.

The agency didn’t disclose the location of the IP address, stating only that it belongs to a “third-party university.”

The research team determined that it is “very unlikely” the backdoor serves as an alternative update mechanism due to the code’s “highly unusual characteristics,” which differ from those of other update mechanisms.

CISA said when the backdoor function on the device is executed, “files on the device are forcibly overwritten” without the knowledge of the end user, so hospitals won’t know what software is running on the device.

By Lily Zhou

Read Full Article on TheEpochTimes.com

Contact Your Elected Officials
The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

Is Believing Seeing?

What if believing in something is not simply the result of seeing it, but the very mechanism that allows it to be seen in the first place?

‘Schools’ Out’

Alice Cooper's biggest hit could be a clarion call for U.S. public education, "Schools Out" because parents are choosing new options.

Fat Propaganda Roundup: Oprah’s Triumph

The vicious jihad that Oprah Winfrey has waged against her own corpulent body mass has concluded, with the pop culture icon as the undisputed victor.

Trump’s SCOTUS “Foreign Interests” Comment Explained

We've addressed claims Trump’s tariffs were illegal, but not his accusation that court members are influenced by foreign interests.

The Party Of Hate Is Unleashing Political Violence

Sec. Scott Bessent placed blame for violence against President Trump squarely on the Democrat Party who are “normalizing this violence. It’s got to stop.”

How Organized Activists Use New Tech, Old Tactics to Disrupt ICE

Activist networks are modernizing old insurgency tactics, such as...

Trump Orders Federal Agencies to Cease All Use of Anthropic Tech

War Secretary Pete Hegseth directed the Department of War...

Bill Clinton says he had ‘no idea’ of Epstein’s crimes during closed-door deposition

Former President Bill Clinton is telling the House Oversight Committee that he had "no idea" of Jeffrey Epstein's crimes at his deposition in Chappaqua, NY.

Federal Judge Rules IRS Illegally Shared Taxpayer Data With ICE

A federal judge on Feb. 26 ruled that the IRS acted illegally by disclosing taxpayer information to Immigration and Customs Enforcement (ICE).

Trump’s Full Statement on Iran

President Trump announced that the United States had begun “major combat operations” in Iran with the goal of eliminating threats from the Iranian regime.

10 Memorable Moments From Trump’s State of the Union Address

President Trump delivered the longest SOYU address in recorded U.S. history, punctuating it with emotional moments and real-life stories to illustrate policy.

Vance Announces New Phase of Fraud Investigations, Withholds $259 Million in Medicaid Funds From Minnesota

VP JD Vance announced new anti-fraud efforts during a press conference with Dr. Mehmet Oz, CMS administrator, targeting waste and abuse.

Trump Proposes New Retirement Account for US Workers Without 401(k) Access

During his State of the Union, President Trump proposed a new retirement program giving Americans without 401(k)s access to savings accounts.
spot_img

Related Articles

Popular Categories

MAGA Business Central