CVE-2025-0683: Contec Health CMS8000 Patient Monitor

Medium severity, CVSS 5.9. EPSS: 0.8% chance of exploitation in the next 30 days.

In its default configuration, Contec Health CMS8000 Patient Monitor transmits plain-text patient data to a hard-coded public IP address when a patient is hooked up to the monitor. This could lead to a leakage of confidential patient data to any device with that IP address or an attacker in a machine-in-the-middle scenario.

Affected products

Published 2025-01-30. Last modified 2026-06-17.