HIGH · 8.4

CVE-2019-25718

Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying operating system through a specific dialog intera...

Vulnerability Description

Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying operating system through a specific dialog interaction. Attackers can exploit this kiosk escape to take control of the operating system and cause the device to display incorrect or no information from the connected Delta Family patient monitor.

CVSS Score

8.4

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DraegerInfinity Explorer C700 Firmware-
DraegerInfinity Explorer C700-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-25718?

CVE-2019-25718 is a vulnerability with a CVSS score of 8.4 (HIGH). Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying operating system through a specific dialog intera...

How severe is CVE-2019-25718?

CVE-2019-25718 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-25718?

Check the references section above for vendor advisories and patch information. Affected products include: Draeger Infinity Explorer C700 Firmware, Draeger Infinity Explorer C700.