Executive brief
The Dräger Infinity Explorer C700, a medical workstation used to display patient monitoring data, contains a vulnerability that allows an individual with physical access to bypass its restricted 'kiosk' interface. By interacting with specific system dialogs, an attacker can gain full control over the underlying operating system. This could lead to the manipulation or loss of critical patient data from connected Delta Family monitors, potentially impacting clinical decision-making and patient safety.
Technical details
A privilege escalation vulnerability exists in the Dräger Infinity Explorer C700 due to improper restriction of UI elements (CWE-451). An attacker with local access to the device can exploit specific dialog interactions to escape the restricted kiosk environment and gain unauthorized access to the underlying operating system. Once the kiosk escape is achieved, the attacker can take full control of the OS, potentially leading to the modification or suppression of patient data received from connected Delta Family monitors. The vulnerability is exploited locally without requiring prior authentication or user interaction beyond the attacker's own actions.
Affected products
- Dräger Infinity Explorer C700
Timeline
- 2026-06-01: advisory: NVD publication date