CVE-2024-12248
CRITICALCVSS 9.8/10EPSS 1.28%
Last modified
CVE-2024-12248 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Contec Health CMS8000 Patient Monitor is vulnerable to an out-of-bounds write, which could allow an attacker to send specially formatted UDP requests in order to write arbitrary data. This could result in remote code execution.. EPSS estimates a 1.28% chance of exploitation in the next 30 days.
Description
Contec Health CMS8000 Patient Monitor is vulnerable to an out-of-bounds write, which could allow an attacker to send specially formatted UDP requests in order to write arbitrary data. This could result in remote code execution.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-12248?
Contec Health CMS8000 Patient Monitor is vulnerable to an out-of-bounds write, which could allow an attacker to send specially formatted UDP requests in order to write arbitrary data. This could result in remote code execution.
How severe is CVE-2024-12248?
CVE-2024-12248 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 1.28% probability of exploitation in the next 30 days.
How do I fix CVE-2024-12248?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-12242Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2024-12243A flaw was found in GnuTLS, which relies on libtasn1 for ASN…5.3
- CVE-2024-12244An issue has been discovered in access controls could allow …4.3
- CVE-2024-12245Logout functionality contains a blind SQL injection that can…8.7
- CVE-2024-12246Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2024-12247Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x…4.3
- CVE-2024-12249The GS Insever Portfolio plugin for WordPress is vulnerable …4.3
- CVE-2024-1225A vulnerability classified as critical was found in QiboSoft…9.8
- CVE-2024-12250The Accept Authorize.NET Payments Using Contact Form 7 plugi…5.3
- CVE-2024-12251In Progress Telerik UI for WinUI versions prior to 2025 Q1 (…7.8
- CVE-2024-12252The SEO LAT Auto Post plugin for WordPress is vulnerable to …9.8
- CVE-2024-12253The Simple Ecommerce Shopping Cart Plugin- Sell products thr…5.4
Are you affected by CVE-2024-12248?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
