← back
CVE-2025-0683highobserved exploitationCWE-359

Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Contec Health CMS8000 Patient Monitor

43Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 8.2epss 0.8%
from disclosure to weapon
Published on NVDJan 30
VulnCheck+355d
exploitation probability
0.8%top 48% of all CVEs
observed exploitation
yesVulnCheck
In its default configuration, Contec Health CMS8000 Patient Monitor transmits plain-text patient data to a hard-coded public IP address when a patient is hooked up to the monitor. This could lead to a leakage of confidential patient data to any device with that IP address or an attacker in a machine-in-the-middle scenario.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N