Nihon Kohden earned ICSMA-25-296-01 for the CNS-6201 central monitor, software 01-03 through 01-06. CVE-2025-59668, a null-pointer dereference, base score 7.5. A remote attacker triggers a denial of service on the central station, which is the nurses-station screen aggregating vitals from every bed it watches. Take it down and you have not hurt one patient, you have blinded a unit.
Jared Quinn of QuinnTech.ai reported it. Nihon Kohden publishes an advisory archive going back years, which is more than most of its peers can say. Availability is a safety property here, not an IT metric. A monitor that crashes is a monitor that is not monitoring.
Questions & Answers
What is CVE-2025-59668?
A null-pointer dereference in the Nihon Kohden CNS-6201 central monitoring station that can be triggered to push it into a denial of service, rated CVSS 7.5 in ICSMA-25-296-01.
Why does taking down a central station matter clinically?
The central station is the screen that aggregates bedside monitors for the whole unit. If it drops, staff lose the single place they watch, so an availability bug here is a patient-safety concern, not just an IT outage.
What can hospitals do now?
Apply the vendor fix from the advisory and make sure the monitoring network is isolated so that only trusted devices can send traffic to the station.