TF-MAL-elf.cms8000_backdoor
📛 Threat Title
Malware family: CMS8000 Backdoor
Description
ThreatFox malware family `elf.cms8000_backdoor`. Printable name: CMS8000 Backdoor.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:digital.nhs.uk
Embedded backdoor function in Contec CMS8000 firmware CISA is advising that all versions of the CMS8000 firmware contain a backdoor to a hardcoded public IP address. Confidential patient data may be exfiltrated by an attacker using this backdoor .
-
web:industrialcyber.co
The research team then discovered what resembles a reverse backdoor within all three of the firmware packages," CISA said. "The reverse backdoor provides automated connectivity to a hard-coded IP address from the Contec CMS8000 devices, allowing the device to download and execute unverified remote files.
-
web:malpedia.caad.fkie.fraunhofer.de
According to CISA, this is an implant found in firmware for the Contec CMS8000 , a patient monitor used by the Healthcare and Public Health sector. An embedded backdoor function with a hard-coded IP address and functionality that enables patient data spillage was identified.
-
web:marbersecurity.com
CISA released a fact sheet, Contec CMS8000 Contains a Backdoor , detailing an analysis of three firmware package versions of the Contec CMS8000 , a patient monitor used by the U.S. Healthcare and Public Health (HPH) sector. Analysts discovered that an embedded backdoor function with a hard-coded IP address, CWE - 912: Hidden Functionality (CVE-2025-0626), and functionality that enables patient ...
-
web:securityaffairs.com
The CMS8000 Patient Monitor is made by China-based company Contec Medical Systems. An anonymous external researcher reported the three vulnerabilities in patient monitors to CISA. The issues are an unauthorized remote control, a backdoor risk, and data exfiltration of personally identifiable information (PII) and protected health information (PHI).
-
web:therecord.media
The Contec CMS8000 , a patient monitor made by a company based in China, has vulnerabilities in its firmware that directly expose it to unauthorized access.
-
web:vulners.com
This fact sheet details an analysis of three firmware package versions of the Contec CMS8000 , a patient monitor used by the U.S. Healthcare and Public Health (HPH) sector. Analysts discovered that an embedded backdoor function with a hard-coded IP a...
-
web:www.cisa.gov
Introduction The Cybersecurity and Infrastructure Security Agency (CISA) analyzed three versions of firmware for the Contec CMS8000 , a patient monitor used by the Healthcare and Public Health sector, and discovered an embedded backdoor function with a hard-coded IP address, CWE - 912: Hidden Functionality (CVE-2025-0626), and functionality that enables patient data spillage, CWE - 359 ...
-
web:www.hipaajournal.com
A remote code execution vulnerability and a hidden backdoor have been identified in the firmware of widely used patient monitors from Contec Health - A backdoor has been identified in Contec CMS8000 and Epsimed MN-120 patient monitors that transmits patient data in plain text to a hard-coded IP address when connected to the Internet. A critical RCE flaw has also been identified that allows ...
-
web:www.redpacketsecurity.com
CISA released a fact sheet, Contec CMS8000 Contains a Backdoor , detailing an analysis of three firmware package versions of the Contec CMS8000 , a patient monitor used by the U.S. Healthcare and Public Health (HPH) sector.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.