CISA, FDA Issue Warning Over Backdoor in China’s Contec Patient Monitors

The Epoch Times Header

FDA recommended hospitals stop using the devices or disconnect them from the internet.

A patient monitor made by Chinese manufacturer Contec contains a backdoor that could allow an attacker to access patient data and remotely manipulate the devices, U.S. authorities said on Friday.

The Contec patient monitor CMS8000 is a device used to monitor human vital signs in hospitals and and clinics in the European Union and the United States.

The Food and Drug Administration (FDA) issued a statement, recommending hospitals and caregivers check Contec CMS8000 monitors, disconnect the device from the internet, or stop using it if the device relies on remote monitoring features.

The recommendation also applies to the same devices relabelled and sold as Epsimed MN-120 patient monitors.

“Once the patient monitor is connected to the internet, it begins gathering patient data, including personally identifiable information (PII) and protected health information (PHI), and exfiltrating (withdrawing) the data outside of the health care delivery environment,” the FDA said.

The device also contains a backdoor that can allow unauthorized persons to cause the device to crash or malfunction, or to corrupt data on the device, the FDA said.

The regulator said it’s not currently aware of any cybersecurity incidents, injuries, or deaths related to the vulnerabilities found on the device. It asked users to report any problems they find.

The vulnerabilities were identified by a research team from the Cybersecurity & Infrastructure Security Agency (CISA), which analyzed three versions of firmware for the Contec CMS8000 patient monitor.

The team found a backdoor that connects the devices to a hard-coded IP address, “allowing the device to download and execute unverified remote files,” CISA said in a report detailing the team’s findings.

The agency didn’t disclose the location of the IP address, stating only that it belongs to a “third-party university.”

The research team determined that it is “very unlikely” the backdoor serves as an alternative update mechanism due to the code’s “highly unusual characteristics,” which differ from those of other update mechanisms.

CISA said when the backdoor function on the device is executed, “files on the device are forcibly overwritten” without the knowledge of the end user, so hospitals won’t know what software is running on the device.

By Lily Zhou

Read Full Article on TheEpochTimes.com

Opinion

Watch: UNREAL PR Disaster Erupts at DNC Summit

The DNC Summit event, intended to showcase liberal and loving Unity™ Through Diversity™, or something to that effect, clearly did not go as planned.

Trump’s Terrifying Yet Terrific Trade Tariffs

President Trump is putting trade tariffs on Canada, Mexico,...

Tulsi vs. The Duopolistic Blob: Senate Showdown Notes

“He who joyfully marches to music rank and file...

Canada Throws Temper Tantrum Over Tariffs

Trump followed through on his promise to tariff Canada and Mexico if they won't stop the flow of drugs and illegal aliens coming over borders by signing an EO.

And the Philadelphia Air Disaster Makes 4 in a Week

We've had 4 air disasters in a week after a record of no incidents since February 12, 2009. when a flight out of Newark, NJ crashed near Buffalo, NY, killing 50 people?

News

Joshua Macias Is The VetVoice

Chairman of the Veterans for Trump Coalition, Joshua Macias,...

NTSB: Conflicting Altimeter Data Retrieved After Midair Collision Near Washington

Investigators found conflicting altimeter readings from the control tower data of the Black Hawk military helicopter and the passenger jet that collided over DC.

FBI Captures Fugitive on 10 Most Wanted List

A fugitive accused of murdering his wife shortly after marriage has been apprehended from Mexico, according to the U.S. Federal Bureau of Investigation (FBI).

McDonald’s to Open Latino Scholarship Program to Non-Latino Applicants

McDonald’s has agreed to stop accepting only Latinos into a scholarship program, as part of a settlement in a lawsuit alleging the program was discriminatory.

Musk Says Trump Has Agreed to Shut Down USAID

Officials are shutting down a federal agency called the U.S. Agency for International Development (USAID) with President Trump’s blessing, Elon Musk said.

Record Number of American CEOs Quit: Report

More U.S. CEOs exited their companies in 2024 than in any year in more than two decades, with economic and technological factors contributing to the trend

White House Says Tariffs Are ‘Necessary Solution’ in Response to Critics

Trump admin issued series of press releases, reaffirming President Donald Trump’s stance on tariffs on Canada, Mexico, and China as a “necessary solution.”
spot_img

Related Articles

Popular Categories

spot_img