s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.cms8000_backdoor

📛 Threat Title

Malware family: CMS8000 Backdoor

Category: CMS8000 Backdoor First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.cms8000_backdoor`. Printable name: CMS8000 Backdoor.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:digital.nhs.uk

    Embedded backdoor function in Contec CMS8000 firmware CISA is advising that all versions of the CMS8000 firmware contain a backdoor to a hardcoded public IP address. Confidential patient data may be exfiltrated by an attacker using this backdoor .

  • web:industrialcyber.co

    The research team then discovered what resembles a reverse backdoor within all three of the firmware packages," CISA said. "The reverse backdoor provides automated connectivity to a hard-coded IP address from the Contec CMS8000 devices, allowing the device to download and execute unverified remote files.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to CISA, this is an implant found in firmware for the Contec CMS8000 , a patient monitor used by the Healthcare and Public Health sector. An embedded backdoor function with a hard-coded IP address and functionality that enables patient data spillage was identified.

  • web:marbersecurity.com

    CISA released a fact sheet, Contec CMS8000 Contains a Backdoor , detailing an analysis of three firmware package versions of the Contec CMS8000 , a patient monitor used by the U.S. Healthcare and Public Health (HPH) sector. Analysts discovered that an embedded backdoor function with a hard-coded IP address, CWE - 912: Hidden Functionality (CVE-2025-0626), and functionality that enables patient ...

  • web:securityaffairs.com

    The CMS8000 Patient Monitor is made by China-based company Contec Medical Systems. An anonymous external researcher reported the three vulnerabilities in patient monitors to CISA. The issues are an unauthorized remote control, a backdoor risk, and data exfiltration of personally identifiable information (PII) and protected health information (PHI).

  • web:therecord.media

    The Contec CMS8000 , a patient monitor made by a company based in China, has vulnerabilities in its firmware that directly expose it to unauthorized access.

  • web:vulners.com

    This fact sheet details an analysis of three firmware package versions of the Contec CMS8000 , a patient monitor used by the U.S. Healthcare and Public Health (HPH) sector. Analysts discovered that an embedded backdoor function with a hard-coded IP a...

  • web:www.cisa.gov

    Introduction The Cybersecurity and Infrastructure Security Agency (CISA) analyzed three versions of firmware for the Contec CMS8000 , a patient monitor used by the Healthcare and Public Health sector, and discovered an embedded backdoor function with a hard-coded IP address, CWE - 912: Hidden Functionality (CVE-2025-0626), and functionality that enables patient data spillage, CWE - 359 ...

  • web:www.hipaajournal.com

    A remote code execution vulnerability and a hidden backdoor have been identified in the firmware of widely used patient monitors from Contec Health - A backdoor has been identified in Contec CMS8000 and Epsimed MN-120 patient monitors that transmits patient data in plain text to a hard-coded IP address when connected to the Internet. A critical RCE flaw has also been identified that allows ...

  • web:www.redpacketsecurity.com

    CISA released a fact sheet, Contec CMS8000 Contains a Backdoor , detailing an analysis of three firmware package versions of the Contec CMS8000 , a patient monitor used by the U.S. Healthcare and Public Health (HPH) sector.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.