Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Cisa and FDA warn about critical back
Global Security

Cisa and FDA warn about critical back

AdminBy AdminJanuary 31, 2025No Comments3 Mins Read
Critical Backdoor in Contec
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


January 31, 2025Red LakshmananVulnerability / healthcare

Critical back in Contec

Agency for cybersecurity and infrastructure of the US (CISA) and the nutrition and medication administration (FDA) issued alerts for hidden functionality in Contec CMS8000 Patient monitors and Epsimed MN-320 patients monitors.

A vulnerabilitytracked as Cve-2025-0626Carries CVSS V4 7.7 on a scale of 10.0. The disadvantage, along with the two other issues, was reported by CISA anonymous external researchers.

“The affected product sends requests to distant access to the hard coded IP address, bypassing the settings of the device,” Cisa – Note In advisory. “This may be the reversible and cause the malicious actor to download and overwrite the files on the device.”

Cybersecurity

“The reverse back provides an automated connection to a solid coded IP address from the CMS8000 devices, which allows the device to download and make unverified deleted files. Publicly available records indicate that the IP address is not related to the manufacturer of medical products or medical facilities but a third university” .

Below are two more identified vulnerabilities in devices – given below –

  • Cve-2014-12248 (CVSS V4 Assessment: 9.3)-Connected vulnerability that can allow the attacker to send specially formatted UDP requests to write arbitrary data, which will lead to a remote code
  • Cve-2025-0683 (CVSS V4 Assessment: 8.2) —The difference of privacy leakage that causes a patient’s transfer to a simple text to a hard coded IP address when the patient is attached to the monitor

Successful Operation CVE-2025-0683 can allow the device with this uncertain IP address to access confidential information about patients or open the door for the enemy on average (AITM) scenario.

Safe holes affect the following products –

  • CMS8000 Patient Monitor: Smart3250-2.27-Wlan2.1.7.cramfs version
  • CMS8000 Patient Monitor: CMS7.820.075/0.74 firmware version (0.75)
  • CMS8000 Patient Monitor: CMS7.820.120.01/0.93 Firmware version (0.95)
  • CMS8000 Patient Monitor: All versions (Cve-2025-0626 and Cve-2025-0683)
Cybersecurity

“These vulnerabilities in cybersecurity can allow unauthorized subjects to bypass cybersecurity, accessing and potentially manipulating,” FDA – NoteAdded that “not knowing about the incidents in cybersecurity, injuries or deaths related to cybersecurity.”

Considering that these vulnerabilities remain unwavering, CISA recommends organizations to disable and delete any CMS8000 device devices from their networks. It is worth noting that the devices are also reinterpreted and sold under the name EPSimed MN-1220.

It is also recommended to check the patients’ monitors for signs of unusual functioning, such as “mismatch between the patients and the patient’s real physical condition.”

CMS8000 Monitor Monitor is made by Contec Medical Systems, the developer of medical products in China, China, Kinhuangdo. On your site, company claim Its products have been approved by FDA and extended to more than 130 countries and regions.

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025

Fedramp at starting speed: obtained lessons

June 18, 2025

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025

Ex-Analytics-Tsru, sentenced to 37 months for leaks of secret documents on national protection

June 18, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025

Fedramp at starting speed: obtained lessons

June 18, 2025

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025

Ex-Analytics-Tsru, sentenced to 37 months for leaks of secret documents on national protection

June 18, 2025

Iran slows the Internet to prevent cyber -napades against the background of escalation of regional conflict

June 18, 2025

RCE Critical Error RCE Rate 9.9 CVSS in Backup and Replication

June 18, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.