Junglewise Threat Intelligence

CVE-2019-25717: Dräger Infinity Delta and Kappa Information Disclosure in Log Files

CVE-2019-25717 · Severity: medium · CVSS 4.3 · Published 2026-06-02

Vendors: Dräger.

Executive brief

Dräger Infinity Delta and Kappa patient monitors, which are used in clinical settings to track patient vital signs, contain a security flaw that exposes internal system logs. An unauthorized person on the same local network could access these logs to view sensitive technical data, including the device's physical location and network configuration. This information could be used to plan further attacks against the hospital's infrastructure or the medical devices themselves.

Technical details

This vulnerability is classified as CWE-538 (Insertion of Sensitive Information into Externally-Accessible File or Directory). The affected Dräger patient monitors fail to restrict access to system log files over the network, allowing unauthenticated attackers with adjacent network access to retrieve them. These logs contain sensitive metadata including device internals, physical location identifiers, and wired network configuration details. The vulnerability affects all software versions of the Infinity Delta, Delta XL, and Kappa product lines. An attacker can exploit this to gain reconnaissance data for further lateral movement or targeted attacks within the clinical network environment.

Affected products

  • Dräger Infinity Delta All software versions
  • Dräger Infinity Delta XL All software versions
  • Dräger Infinity Kappa All software versions

Timeline

  • 2026-06-02: advisory: NVD and VulnCheck published advisory details.

References

Related threats