Vulnerability Description
Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated network attackers to access log files over a network connection. Attackers can retrieve device internals, location information, and wired network configuration details from the exposed log files.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Draeger | Infinity Delta Firmware | - |
| Draeger | Infinity Delta | - |
| Draeger | Delta Xl Firmware | - |
| Draeger | Delta Xl | - |
| Draeger | Kappa Firmware | - |
| Draeger | Kappa | - |
Related Weaknesses (CWE)
References
- https://static.draeger.com/securityVendor Advisory
- https://www.vulncheck.com/advisories/dr-ger-infinity-delta-kappa-patient-monitorThird Party AdvisoryVDB Entry
FAQ
What is CVE-2019-25717?
CVE-2019-25717 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated network attackers to access log files over a network connection....
How severe is CVE-2019-25717?
CVE-2019-25717 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-25717?
Check the references section above for vendor advisories and patch information. Affected products include: Draeger Infinity Delta Firmware, Draeger Infinity Delta, Draeger Delta Xl Firmware, Draeger Delta Xl, Draeger Kappa Firmware.