Vulnerability Description
Dräger Infinity M300 patient worn monitors with software version VG2.x and earlier contain a network-based denial of service vulnerability that allows attackers with access to the hospital or Infinity Network to repeatedly trigger device reboots until the device enters a fail state requiring manual restart. Attackers can exploit this vulnerability to cause loss of wireless network connectivity, temporary loss of patient monitoring, and interruption of alarm functionality until the device is manually recovered.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://static.draeger.com/security/download/2019-277-02-M300-VG2x-Security-Advi
- https://www.vulncheck.com/advisories/dr-ger-infinity-m300-vg2-x-network-based-de
FAQ
What is CVE-2019-25724?
CVE-2019-25724 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Dräger Infinity M300 patient worn monitors with software version VG2.x and earlier contain a network-based denial of service vulnerability that allows attackers with access to the hospital or Infinity...
How severe is CVE-2019-25724?
CVE-2019-25724 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-25724?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.