Update 2/4/25: A new report from Claroty states that they purchased the Contec CMS8000 device and, after analyzing its firmware, believe the behavior described by CISA and the FDA is actually an auto-update mechanism and not a backdoor. According to Claroty, the manual instructs admins to configure the monitor's central monitoring center to a public IP address of 202.114.4.119, the IP address seen by CISA. Furthermore, the researchers say that the update routine can only be triggered when booting the system and pressing a button on the device. "Team82 was only able to trigger the update logic when booting the device AND clicking a button on the device (press "C" - main button). To the best of our knowledge, this is the only way to trigger the update logic. If true, this would require an attacker to be physically located near the device," reads the Claroty report. "Although the full update process is VERY dangerous and risky, to us it does not appear to have malicious intent behind it, especially when considering the manual boldly refers to this IP address, and white-label vendors ask users to configure their internal CMS with this IP address." However, as the IP address specified in the manual is a public address in China, it could lead to inadvertent data leaks and takeover risks if an NFS server is running. Currently, no NFS server is configured at this IP address. Claroty warns that the insecure design of the device's update mechanism is still a serious security concern, ...
Backdoor found in two healthcare patient monitors, linked to IP in China
BleepingComputer
·Lawrence Abrams
·Published Jan 30, 2025
·Updated
Affected Software
2 affected components
Contec CMS8000
Epsimed MN-120
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the discovery of a backdoor in healthcare patient monitors linked to IP addresses in China.
2
What security implications are discussed in the article?
The security implications include potential unauthorized access to sensitive healthcare data and risks to patient privacy.
3
What products are specifically mentioned as affected?
The affected products mentioned are the Contec CMS8000 and the Epsimed MN-120 patient monitors.
4
Who discovered the backdoor and what method did they use?
The backdoor was discovered by Claroty, who analyzed the firmware of the Contec CMS8000 device.
5
What did the analysis by Claroty suggest regarding the backdoor behavior?
Claroty's analysis suggested that the behavior might be an auto-update mechanism rather than an actual backdoor.