CISA, FDA Issue Warning Over Backdoor in China’s Contec Patient Monitors

5Mind. The Meme Platform
The Epoch Times Header

FDA recommended hospitals stop using the devices or disconnect them from the internet.

A patient monitor made by Chinese manufacturer Contec contains a backdoor that could allow an attacker to access patient data and remotely manipulate the devices, U.S. authorities said on Friday.

The Contec patient monitor CMS8000 is a device used to monitor human vital signs in hospitals and and clinics in the European Union and the United States.

The Food and Drug Administration (FDA) issued a statement, recommending hospitals and caregivers check Contec CMS8000 monitors, disconnect the device from the internet, or stop using it if the device relies on remote monitoring features.

The recommendation also applies to the same devices relabelled and sold as Epsimed MN-120 patient monitors.

“Once the patient monitor is connected to the internet, it begins gathering patient data, including personally identifiable information (PII) and protected health information (PHI), and exfiltrating (withdrawing) the data outside of the health care delivery environment,” the FDA said.

The device also contains a backdoor that can allow unauthorized persons to cause the device to crash or malfunction, or to corrupt data on the device, the FDA said.

The regulator said it’s not currently aware of any cybersecurity incidents, injuries, or deaths related to the vulnerabilities found on the device. It asked users to report any problems they find.

The vulnerabilities were identified by a research team from the Cybersecurity & Infrastructure Security Agency (CISA), which analyzed three versions of firmware for the Contec CMS8000 patient monitor.

The team found a backdoor that connects the devices to a hard-coded IP address, “allowing the device to download and execute unverified remote files,” CISA said in a report detailing the team’s findings.

The agency didn’t disclose the location of the IP address, stating only that it belongs to a “third-party university.”

The research team determined that it is “very unlikely” the backdoor serves as an alternative update mechanism due to the code’s “highly unusual characteristics,” which differ from those of other update mechanisms.

CISA said when the backdoor function on the device is executed, “files on the device are forcibly overwritten” without the knowledge of the end user, so hospitals won’t know what software is running on the device.

By Lily Zhou

Read Full Article on TheEpochTimes.com

Contact Your Elected Officials
The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

Jill Biden, The Doctor Of Dishonesty

Dr. Jill Biden, our nation’s former First Lady, is a notorious liar. Throughout her husband’s four-year term as President, she frequently lied about his health.

Facts Are Now Racist? As A Society, We’re Cooked!

If the way you think about another person is based on nothing but the other person’s race, hate to break it to you, but that is racism.

The ballot’s mission creep

Elections are meant to be about ideas, policies, and competence, not personal characteristics that have little bearing on a candidate’s ability to serve.

Tyranny in Virginia

Tyrants are forever in the sights of Progressive politicos....

WATCH: Larry Fink Demands Access to Americans’ Savings, Pension Funds to Bankroll AI

Larry Fink appeared at the “National Skilled Trades Day,” hosted by Texas State Technical College to recruit the electricians he needs to complete the destruction of his AI Death Star.

New Jersey State Police Sets up Protest Zone Outside Immigration Detention Center

Secretary of Homeland Security Markwayne Mullin welcomed the governor’s move to deploy state police to restore order outside the Delaney Hall.

Trump Directs Agencies to Align With Study Recommending Fewer Childhood Vaccines

President Trump signed an executive order directing agencies to align with a scientific assessment that recommended fewer childhood vaccines.

Judge Seeks DOJ Explanation on Bid to Vacate Convictions for Unpardoned Jan. 6 Defendants

A federal judge delayed ruling on the DOJ’s request to vacate convictions tied to the Jan. 6 Capitol breach, citing a need for more information.

Iranian National Used Fake US Company IDs to Steal Military-Grade Technology for Tehran, Treasury Says

Iranian national allegedly used fake U.S. business identities to defrauded dozens of U.S. IT vendors of millions of dollars’ worth of restricted goods.

Trump Suggests Vance’s Anti-Fraud Efforts Could Save Social Security

The president made the comment at a Cabinet meeting...

Trump’s Triumphal Arch Approved by Federal Commission

A commission has approved President Donald Trump’s triumphal arch just outside of Washington, a key step toward making the project a reality.

Trump Details Military Complex Above and Below New White House Ballroom

Trump says planned White House ballroom will be the “safest building ever built,” serving ceremonial and national security purposes.

Senate Confirms 49 Trump Nominees, Including Key Energy Officials

The Senate has confirmed 49 nominees selected by President Trump, including officials tapped to oversee federal land management and energy policy.
spot_img

Related Articles

Popular Categories

MAGA Business Central