Back to overview

CVE-2019-25720

MEDIUM
6.5
CVSS 3.1
Description
Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain a denial-of-service vulnerability in all software versions that allows unauthenticated attackers to reboot the monitor by sending a malformed network packet. Attackers can repeatedly send such malformed packets to disrupt patient monitoring until the device falls back to default configuration and loses network connectivity.

Metadata

CVE ID
CVE-2019-25720
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-06-02 14:22 UTC
Published
2026-06-03 16:56 UTC
Last updated
2026-06-03 17:44 UTC
Primary CWE
CWE-1286
CWE-1286 Improper Validation of Syntactic Correctness of Inp…
Vendor / Product
Dräger / SC 6002XL
Sources
cve.org  ·  NVD

Severity & Metrics

6.5 MEDIUM CVSS 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (5)
VendorProductPlatformVersions
Dräger SC 6002XL SC 6002XL
Dräger SC 7000 SC 7000
Dräger SC6802XL SC6802XL
Dräger SC8000 SC8000
Dräger SC90000 XL SC90000 XL
Weakness (CWE)
CWESourceDescription
CWE-1286 cna CWE-1286 Improper Validation of Syntactic Correctness of Input
CVSS scores (2)
ScoreSeverityVersionSourceVector
7.1 HIGH 4.0 cna CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
6.5 MEDIUM 3.1 cna CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Back to overview