Infosec in brief The United States Food and Drug Administration has told medical facilities and caregivers that monitor patients using Contec equipment to disconnect the devices from the internet ASAP. The Contec CMS8000, also sold as the Epsimed MN-120, contains a trio of vulnerabilities (CVE-2024-12248, CVSS 9.3; CVE-2025-0626, CVSS 7.5; and CVE-2025-0683, CVSS 5.9) that the Cybersecurity and Infrastructure Security Agency (CISA) last week warned could allow an attacker to remotely execute code, crash the device and, most alarmingly, exfiltrate information about patients. "Once the patient monitor is connected to the internet, it begins gathering patient data, including personally identifiable information and protected health information, and exfiltrating the data outside of the health care delivery environment," the FDA said of the hardcoded hole. The FDA recommends that anyone with a CMS8000 unplug it from the internet and disable its Wi-Fi immediately, and stop using it to remotely monitor patients. While neither the FDA nor CISA believe there have been any cybersecurity incidents related to the devices, it's possible any left online could be compromised, and used by an attacker to move laterally to further compromise a connected network. To make matters worse, CISA said in a factsheet about the vulnerability that it doesn't believe the backdoor is related to remote software updates - this appears to be all about harvesting data. "The [back door] provides neither an inte...
Medical monitoring machines spotted stealing patient data, users warned to pull the plug ASAP
The Register
·Brandon Vigliarolo
·Published Feb 3, 2025
·Updated
Affected Software
4 affected components
Contec CMS8000
Epsimed MN-120
Contec CMS8000
Contec Epsimed MN-120
Frequently Asked Questions
1
What is the main issue discussed in this article?
The article highlights a security vulnerability in Contec medical monitoring devices that are suspected of leaking patient data.
2
What actions have been recommended by the FDA regarding the affected devices?
The FDA has advised medical facilities and caregivers to immediately disconnect the affected Contec patient monitoring devices from the internet.
3
Which specific medical monitoring devices are mentioned as being at risk?
The Contec CMS8000 and Epsimed MN-120 medical monitoring devices are specifically mentioned as being compromised.
4
What type of data is at risk due to this vulnerability?
Patient data is at risk of being stolen due to the compromised security of these medical monitoring machines.
5
Who is responsible for the equipment that has been identified as compromised?
The devices are manufactured by Contec and Epsimed, who are responsible for the affected medical monitoring equipment.