MEDIUM · 6.5

CVE-2018-19014

Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Log files are accessible over an unauthenticated network conn...

Vulnerability Description

Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Log files are accessible over an unauthenticated network connection. By accessing the log files, an attacker is able to gain insights about internals of the patient monitor, the location of the monitor, and wired network configuration.

CVSS Score

6.5

MEDIUM

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
DraegerKappa FirmwareAll versions
DraegerKappa-
DraegerInfinity Explorer C700 FirmwareAll versions
DraegerInfinity Explorer C700-
DraegerDelta Xl FirmwareAll versions
DraegerDelta Xl-
DraegerInfinity Delta FirmwareAll versions
DraegerInfinity Delta-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-19014?

CVE-2018-19014 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Log files are accessible over an unauthenticated network conn...

How severe is CVE-2018-19014?

CVE-2018-19014 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-19014?

Check the references section above for vendor advisories and patch information. Affected products include: Draeger Kappa Firmware, Draeger Kappa, Draeger Infinity Explorer C700 Firmware, Draeger Infinity Explorer C700, Draeger Delta Xl Firmware.