logo

CISA Warns of Backdoor in Contec CMS8000 Patient Monitors

ID: 37ada96b-7aa4-504d-b07c-794af7eb1c0b

STIX ID: report--37ada96b-7aa4-504d-b07c-794af7eb1c0b

Feed Name: SOCRadar Blog

Threat Score
75/100

Date Published: 2025-01-31

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

CISA warns that Contec CMS8000 patient monitors contain an embedded backdoor in multiple firmware versions that connects to a hard-coded IP (linked to an unrelated university) to download and execute unverified files and transmit patient data; this creates risks of remote code execution, unauthorized data exfiltration, and makes detection difficult due to lack of logging. CISA recommends isolating devices, restricting access, monitoring and blocking suspicious IPs, disabling unnecessary services, using tamper-evident seals, and applying firmware updates if available; Contec has not responded to remediation requests.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.