#VU103468 Information disclosure in CMS8000 Patient Monitor - CVE-2025-0683
Published: January 31, 2025
CMS8000 Patient Monitor
Contec
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the affected product transmits plain-text patient data to a hard-coded public IP address when a patient is hooked up to the monitor. A remote attacker can gain unauthorized access to sensitive information on the system.