Description
Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service vulnerability that allows remote attackers to cause the monitor to reboot by sending a malformed network packet. Attackers can repeatedly send malformed network packets to disrupt patient monitoring until the device falls back to default configuration and loses network connectivity.
Problem types
CWE-15 External Control of System or Configuration Setting
Product status
Infinity Delta (custom)
Infinity Delta XL (custom)
Infinity Kappa (custom)
Credits
Marc Ruef and Rocco Gagliardi, scip AG
References
static.draeger.com/...ity-delta-vf10-1-security-advisory.pdf
www.vulncheck.com/...onitor-dos-via-malformed-network-packet