CVE-2025-0683: Contec Health CMS8000 Patient Monitor
Medium severity, CVSS 5.9. EPSS: 0.8% chance of exploitation in the next 30 days.
In its default configuration, Contec Health CMS8000 Patient Monitor transmits plain-text patient data to a hard-coded public IP address when a patient is hooked up to the monitor. This could lead to a leakage of confidential patient data to any device with that IP address or an attacker in a machine-in-the-middle scenario.
Affected products
- Contec Health CMS8000 Patient Monitor: any version
Published 2025-01-30. Last modified 2026-06-17.