Home

Description

Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain a denial-of-service vulnerability in all software versions that allows unauthenticated attackers to reboot the monitor by sending a malformed network packet. Attackers can repeatedly send such malformed packets to disrupt patient monitoring until the device falls back to default configuration and loses network connectivity.

PUBLISHED Reserved 2026-06-02 | Published 2026-06-03 | Updated 2026-06-03 | Assigner VulnCheck




HIGH: 7.1CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

MEDIUM: 6.5CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-1286 Improper Validation of Syntactic Correctness of Input

Product status

Default status
unknown

SC 6002XL (custom)
affected

Default status
unknown

SC6802XL (custom)
affected

Default status
unknown

SC 7000 (custom)
affected

Default status
unknown

SC8000 (custom)
affected

Default status
unknown

SC90000 XL (custom)
affected

Credits

Jeroen Slobbe and Max Grim finder

References

static.draeger.com/...9000-security-advisory-update-v1-5.pdf vendor-advisory

www.vulncheck.com/...evices-dos-via-malformed-network-packet third-party-advisory

cve.org (CVE-2019-25720)

nvd.nist.gov (CVE-2019-25720)

Download JSON