Last week, the Cybersecurity and Infrastructure Security Agency (CISA), alongside the US Food and Drug Administration (FDA), raised an alert for Contec CMS8000 and Epsimed MN-120 healthcare monitors, warning they potentially put patients at risk once connected to the Internet, due to a malicious, hidden backdoor embedded into the devices. But security researchers say the issue isn't actually intentional malware but, rather, just insecure design. The devices continuously monitor patient vital signs, such as heart rate, blood oxygen saturation, temperature, respiration rate, and more. CISA and the FDA reported findings for three cybersecurity risks in the gear thanks to the "backdoor": an unauthorized user could remotely control a monitor and cause it to function in an unintended manner; attackers could compromise the device and pivot to a network; and an attacker could exfiltrate the data that the monitor collects. From a patient health perspective, if an attacker were able to manipulate the information the monitor gives patients, that could prevent them from realizing that there's something wrong. Though they reported no known cybersecurity incidents, deaths, or injuries related to the findings, the FDA still provided recommendations for patients and caregivers: talking to healthcare providers about evaluating their patient monitoring device and following certain steps if it does rely on an Internet connection. The FDA also tasked healthcare providers with checking their pati...
Agencies Sound Alarm on Patient Monitors With Hardcoded Backdoor
Dark Reading
·Kristina Beek
·Published Feb 6, 2025
·Updated
Affected Software
4 affected components
Contec CMS8000
Epsimed MN-120
Contec CMS8000
Epsimed MN-120
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a security alert issued for healthcare monitors with hardcoded backdoors.
2
What security implications are discussed regarding patient monitors?
The hardcoded backdoors in the Contec CMS8000 and Epsimed MN-120 monitors could allow unauthorized access to patient data.
3
Which agencies issued the alert about the patient monitors?
The alert was issued by the Cybersecurity and Infrastructure Security Agency (CISA) and the US Food and Drug Administration (FDA).
4
What products are specifically mentioned as affected in the alert?
The affected products are the Contec CMS8000 and Epsimed MN-120 healthcare monitors.
5
Why is the security issue with these monitors concerning for healthcare providers?
The presence of backdoors can jeopardize patient safety and confidentiality, leading to potential exploitation.