CVE-2025-0683 Details
Description
In its default configuration, Contec Health CMS8000 Patient Monitor transmits plain-text patient data to a hard-coded public IP address when a patient is hooked up to the monitor. This could lead to a leakage of confidential patient data to any device with that IP address or an attacker in a machine-in-the-middle scenario.
A vulnerability exists in the Contec Health CMS8000 Patient Monitor, all versions, allowing for the unauthorized transmission of plain-text patient data to a hard-coded public IP address in China. This data exfiltration occurs when the monitor is in use, potentially leading to privacy violations and unauthorized access to sensitive health information. The issue has been linked to a backdoor in the device's firmware, which could allow for remote code execution and manipulation of the device.
The FDA has advised against using the Contec CMS8000 Patient Monitor or the Epsimed MN-120 Patient Monitor, which is a re-labeled version of the CMS8000, due to these vulnerabilities. Health care providers should check for signs of tampering or unusual device behavior. If the monitor is connected to the internet, it should be unplugged and not used until an alternative is found. For those who cannot remove the devices from their networks, CISA recommends blocking the IP address 202.114.4.119 and reviewing network firewall rules to prevent access to potentially affected devices.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 30, 2025CISA-ADP
Assessed Jan 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-359 | Exposure of Private Personal Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Contec Health CMS8000 | smart3250-2.6.27-wlan2.1.7.cramfs CMS7.820.075.08/0.74(0.75) CMS7.820.120.01/0.93(0.95) |
CPE
Remediation
| |
| Epsimed MN-120 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 31, 2025 | CVE Modified | [email protected] |
| Jan 31, 2025 | CVE Modified | CVE |
| Jan 30, 2025 | New CVE Received | [email protected] |
Volerion