Critical ‘Backdoor’ Discovered in Widely Used Healthcare Patient Monitors
ID: c3aaea7c-0603-5e14-b29e-5f4331b9b6d1
STIX ID: report--c3aaea7c-0603-5e14-b29e-5f4331b9b6d1
Feed Name: Security Boulevard
On January 30, 2025 the FDA and CISA disclosed that Contec CMS8000 (and Epsimed MN-120) patient monitors contain a persistent backdoor in firmware that mounts an NFS share from a hard-coded IP, can copy remote files (potentially modifying device firmware), streams patient data over LPD to port 5151, and may allow remote code execution; no patch is available, no incidents have been reported, and stakeholders are advised to disable network connectivity and rely on local monitoring or replace affected devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
