Executive brief
Dräger SC series patient monitoring devices are used in healthcare settings to track vital signs. A vulnerability allows an attacker on the same local network to remotely crash and reboot these monitors by sending a specifically crafted network packet. Repeated attacks can cause the device to lose network connectivity and revert to default settings, potentially disrupting critical patient care and monitoring operations.
Technical details
A denial-of-service vulnerability exists in Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) due to improper validation of syntactic correctness of input (CWE-1286). An unauthenticated attacker with adjacent network access can trigger a device reboot by sending a malformed network packet. If the attack is sustained, the device may eventually fall back to a default configuration and lose its network connection. The vulnerability affects all software versions of the listed models.
Affected products
- Dräger SC 6002XL All software versions
- Dräger SC 6802XL All software versions
- Dräger SC 7000 All software versions
- Dräger SC 8000 All software versions
- Dräger SC 9000 XL All software versions
Timeline
- 2026-06-03: advisory: NVD and VulnCheck published advisory details.