Vulnerability Description
Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service vulnerability that allows remote attackers to cause the monitor to reboot by sending a malformed network packet. Attackers can repeatedly send malformed network packets to disrupt patient monitoring until the device falls back to default configuration and loses network connectivity.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Draeger | Infinity Delta Firmware | All versions |
| Draeger | Infinity Delta | - |
| Draeger | Delta Xl Firmware | All versions |
| Draeger | Delta Xl | - |
| Draeger | Kappa Firmware | All versions |
| Draeger | Kappa | - |
Related Weaknesses (CWE)
References
- https://static.draeger.com/security/download/2019-01-22-draeger-infinity-delta-vVendor Advisory
- https://www.vulncheck.com/advisories/dr-ger-infinity-delta-kappa-patient-monitorThird Party AdvisoryVDB Entry
FAQ
What is CVE-2019-25716?
CVE-2019-25716 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service vulnerability that allows remote attackers to cause the monitor to reboot by sending a malformed network packet....
How severe is CVE-2019-25716?
CVE-2019-25716 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-25716?
Check the references section above for vendor advisories and patch information. Affected products include: Draeger Infinity Delta Firmware, Draeger Infinity Delta, Draeger Delta Xl Firmware, Draeger Delta Xl, Draeger Kappa Firmware.