Junglewise Threat Intelligence

CVE-2019-25716: Dräger Infinity Patient Monitors denial of service via malformed packet

CVE-2019-25716 · Severity: medium · CVSS 6.5 · Published 2026-06-01

Vendors: Dräger.

Executive brief

Dräger Infinity patient monitors, which are used in clinical settings to track vital signs, are vulnerable to a remote attack that causes the device to crash and reboot. An attacker on the same local network can repeatedly trigger these reboots, potentially forcing the device to reset to factory defaults and lose network connectivity. This disruption prevents medical staff from receiving real-time patient data, posing a risk to patient safety and clinical operations.

Technical details

A denial-of-service vulnerability exists in the network stack of Dräger Infinity Delta, Delta XL, and Kappa patient monitors. The flaw is triggered by the receipt of a malformed network packet, which causes the device to undergo an unplanned reboot. An attacker with adjacent network access (e.g., on the same hospital subnet) can exploit this without authentication. Repeated exploitation can lead to a persistent denial-of-service state where the device reverts to its default configuration and loses its network connection. The vulnerability is tracked as CWE-15 (External Control of System or Configuration Setting).

Affected products

  • Dräger Infinity Delta
  • Dräger Infinity Delta XL
  • Dräger Infinity Kappa

Timeline

  • 2026-06-01: advisory: NVD publication date

References

Related threats