CISA Warns of Backdoor in Contec CMS8000 Patient Monitors
ID: 37ada96b-7aa4-504d-b07c-794af7eb1c0b
STIX ID: report--37ada96b-7aa4-504d-b07c-794af7eb1c0b
Feed Name: SOCRadar Blog
CISA warns that Contec CMS8000 patient monitors contain an embedded backdoor in multiple firmware versions that connects to a hard-coded IP (linked to an unrelated university) to download and execute unverified files and transmit patient data; this creates risks of remote code execution, unauthorized data exfiltration, and makes detection difficult due to lack of logging. CISA recommends isolating devices, restricting access, monitoring and blocking suspicious IPs, disabling unnecessary services, using tamper-evident seals, and applying firmware updates if available; Contec has not responded to remediation requests.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
