Vulnerability Description
Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying operating system through a specific dialog interaction. Attackers can exploit this kiosk escape to take control of the operating system and cause the device to display incorrect or no information from the connected Delta Family patient monitor.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Draeger | Infinity Explorer C700 Firmware | - |
| Draeger | Infinity Explorer C700 | - |
Related Weaknesses (CWE)
References
- https://static.draeger.com/security/download/2019-01-22-draeger-infinity-delta-vVendor Advisory
- https://www.vulncheck.com/advisories/dr-ger-infinity-explorer-c700-privilege-escThird Party AdvisoryVDB Entry
FAQ
What is CVE-2019-25718?
CVE-2019-25718 is a vulnerability with a CVSS score of 8.4 (HIGH). Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying operating system through a specific dialog intera...
How severe is CVE-2019-25718?
CVE-2019-25718 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-25718?
Check the references section above for vendor advisories and patch information. Affected products include: Draeger Infinity Explorer C700 Firmware, Draeger Infinity Explorer C700.