CVE-2025-0683

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
30/01/2025
Last modified:
31/01/2025

Description

In its default configuration, Contec Health CMS8000 Patient Monitor transmits plain-text <br /> patient data to a hard-coded public IP address when a patient is hooked <br /> up to the monitor. This could lead to a leakage of confidential patient <br /> data to any device with that IP address or an attacker in a <br /> machine-in-the-middle scenario.