Contechealth's vulnerability profile centers on its CMS8000 patient-monitoring system and associated firmware, a specialized medical-device platform. The observed weaknesses cluster around access-control implementation, resource-consumption handling, and debug-code exposure, reflecting common configuration and development-practice issues in embedded medical appliances.
The number and severity of CVEs published that impact products developed by Contechealth over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-38100HIGH The CMS800 device fails while attempting to parse malformed network data sent by a threat actor. A threat actor with network access can remotely issue a specially formatted UDP req | Sep 13, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-38069MEDIUM Multiple globally default credentials exist across all CMS8000 devices, that once exposed, allow a threat actor with momentary physical access to gain privileged access to any devi | Sep 13, 2022 | 6.1 | 21 | NO | NO |
CVE-2022-3027MEDIUM The CMS8000 device does not properly control or sanitize the SSID name of a new Wi-Fi access point. A threat actor could create an SSID with a malicious name, including non-standar | Sep 13, 2022 | 5.7 | 20 | NO | NO |
CVE-2022-38453MEDIUM Multiple binary application files on the CMS8000 device are compiled with 'not stripped' and 'debug_info' compilation settings. These compiler settings greatly decrease the level o | Sep 13, 2022 | 4.4 | 18 | NO | NO |
CVE-2022-36385MEDIUM A threat actor with momentary access to the device can plug in a USB drive and perform a malicious firmware update, resulting in permanent changes to device functionality. No authe | Sep 13, 2022 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Contechealth.
Media articles that mention a CVE ID that affects a product developed by Contechealth — matched by CVE ID, not by vendor name.