CVE-2024-12248: Contec Health CMS8000 Patient Monitor

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

Contec Health CMS8000 Patient Monitor is vulnerable to an out-of-bounds write, which could allow an attacker to send specially formatted UDP requests in order to write arbitrary data. This could result in remote code execution.

Affected products

Published 2025-01-30. Last modified 2026-06-17.