Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: ransomnote

 Backdoor found in two healthcare patient monitors, linked to IP in China
BleepingComputer ^ | 1/30/2025 | Lawrence Abrams

Posted on 1/31/2025, 10:49:05 PM by Pete from Shawnee Mission

The US Cybersecurity and Infrastructure Security Agency (CISA) is warning that Contec CMS8000 devices, a widely used healthcare patient monitoring device, include a backdoor that quietly sends patient data to a remote IP address and downloads and executes files on the device.

Contec is a China-based company that specializes in healthcare technology, offering a range of medical devices including patient monitoring systems, diagnostic equipment, and laboratory instruments.

CISA learned of the malicious behavior from an external researcher who disclosed the vulnerability to the agency. When CISA tested three Contec CMS8000 firmware packages, the researchers discovered anomalous network traffic to a hard-coded external IP address, which is not associated with the company but rather a university.

This led to the discovery of a backdoor in the company's firmware that would quietly download and execute files on the device, allowing for remote execution and the complete takeover of the patient monitors. It was also discovered that the device would quietly send patient data to the same hard-coded address when devices were started. (additional info at link.)


22 posted on 01/31/2025 9:26:06 PM PST by ransomnote (IN GOD WE TRUST)
[ Post Reply | Private Reply | To 18 | View Replies ]


To: ransomnote
"According to federal data, the flow from Terminus Dam into the Kaweah River near Visalia increased from 57 cubic feet per second to more than 1,500 on Friday morning. The flow from Lake Success near Porterville into the Tule River increased from 105 cubic feet per second to 990. "
25 posted on 01/31/2025 9:28:36 PM PST by ransomnote (IN GOD WE TRUST)
[ Post Reply | Private Reply | To 22 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson