Metrics
Affected Vendors & Products
Solution
Per FDA recommendation, CISA recommends users remove any Contec CMS8000 devices from their networks. Please note that this device may be re-labeled and sold by resellers. For a list of known re-labeled devices, please refer to FDA's safety communication https://www.fda.gov/medical-devices/safety-communications/cybersecurity-vulnerabilities-certain-patient-monitors-contec-and-epsimed-fda-safety-communication .
Workaround
No workaround given by the vendor.
Wed, 12 Feb 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 31 Jan 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The affected product is vulnerable to an out-of-bounds write, which could allow an attacker to send specially formatted UDP requests in order to write arbitrary data. This could result in remote code execution. | Contec Health CMS8000 Patient Monitor is vulnerable to an out-of-bounds write, which could allow an attacker to send specially formatted UDP requests in order to write arbitrary data. This could result in remote code execution. |
References |
| |
Metrics |
cvssV3_1
|
Thu, 30 Jan 2025 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The affected product is vulnerable to an out-of-bounds write, which could allow an attacker to send specially formatted UDP requests in order to write arbitrary data. This could result in remote code execution. | |
Title | Out-of-bounds Write vulnerability in Contec Health CMS8000 Patient Monitor | |
Weaknesses | CWE-787 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-02-12T16:53:16.892Z
Reserved: 2024-12-05T15:20:44.585Z
Link: CVE-2024-12248

Updated: 2025-02-12T16:53:11.868Z

Status : Received
Published: 2025-01-30T19:15:13.390
Modified: 2025-01-31T17:15:11.797
Link: CVE-2024-12248

No data.

No data.