VYPR

CMS8000

by Contec Co., Ltd.

CVEs (4)

  • CVE-2024-12248CriJan 30, 2025
    risk 0.64cvss 9.8epss 0.01

    Contec Health CMS8000 Patient Monitor is vulnerable to an out-of-bounds write, which could allow an attacker to send specially formatted UDP requests in order to write arbitrary data. This could result in remote code execution.

  • CVE-2025-1204HigFeb 25, 2025
    risk 0.50cvss epss 0.00

    The "update" binary in the firmware of the affected product sends attempts to mount to a hard-coded, routable IP address, bypassing existing device network settings to do so. The function triggers if the 'C' button is pressed at a specific time during the boot process. If an…

  • CVE-2025-0626HigJan 30, 2025
    risk 0.49cvss 7.5epss 0.01

    The "monitor" binary in the firmware of the affected product attempts to mount to a hard-coded, routable IP address, bypassing existing device network settings to do so. The function also enables the network interface of the device if it is disabled. The function is triggered by…

  • CVE-2025-0683MedJan 30, 2025
    risk 0.38cvss 5.9epss 0.01

    In its default configuration, Contec Health CMS8000 Patient Monitor transmits plain-text patient data to a hard-coded public IP address when a patient is hooked up to the monitor. This could lead to a leakage of confidential patient data to any device with that IP address or…