Contec Health CMS8000 Patient Monitor Privacy Leakage Vulnerability

Vulnerability

A vulnerability exists in the Contec Health CMS8000 Patient Monitor, all versions, allowing for the unauthorized transmission of plain-text patient data to a hard-coded public IP address in China. This data exfiltration occurs when the monitor is in use, potentially leading to privacy violations and unauthorized access to sensitive health information. The issue has been linked to a backdoor in the device's firmware, which could allow for remote code execution and manipulation of the device.

Impact

Exploitation of this vulnerability could result in unauthorized access to and exfiltration of confidential patient data, including personally identifiable information and protected health information, to the hard-coded IP address in China. Additionally, the backdoor in the device's firmware could be used for remote code execution and unauthorized control of the patient monitor.

Remediation

The FDA has advised against using the Contec CMS8000 Patient Monitor or the Epsimed MN-120 Patient Monitor, which is a re-labeled version of the CMS8000, due to these vulnerabilities. Health care providers should check for signs of tampering or unusual device behavior. If the monitor is connected to the internet, it should be unplugged and not used until an alternative is found. For those who cannot remove the devices from their networks, CISA recommends blocking the IP address 202.114.4.119 and reviewing network firewall rules to prevent access to potentially affected devices.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.3
remediation
8.3
relevance
0.0
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.