Description
Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated network attackers to access log files over a network connection. Attackers can retrieve device internals, location information, and wired network configuration details from the exposed log files.
Problem types
CWE-538 Insertion of Sensitive Information into Externally-Accessible File or Directory
Product status
all software versions (custom)
all software versions (custom)
all software versions (custom)
Credits
Marc Ruef and Rocco Gagliardi, scip AG
References
static.draeger.com/security
www.vulncheck.com/...ors-unauthenticated-log-file-disclosure