Junglewise Threat Intelligence

CVE-2019-25720: Dräger SC Monitoring devices denial of service via malformed packet

CVE-2019-25720 · Severity: medium · CVSS 6.5 · Published 2026-06-03

Vendors: Dräger.

Executive brief

Dräger SC series patient monitoring devices are used in healthcare settings to track vital signs. A vulnerability allows an attacker on the same local network to remotely crash and reboot these monitors by sending a specifically crafted network packet. Repeated attacks can cause the device to lose network connectivity and revert to default settings, potentially disrupting critical patient care and monitoring operations.

Technical details

A denial-of-service vulnerability exists in Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) due to improper validation of syntactic correctness of input (CWE-1286). An unauthenticated attacker with adjacent network access can trigger a device reboot by sending a malformed network packet. If the attack is sustained, the device may eventually fall back to a default configuration and lose its network connection. The vulnerability affects all software versions of the listed models.

Affected products

  • Dräger SC 6002XL All software versions
  • Dräger SC 6802XL All software versions
  • Dräger SC 7000 All software versions
  • Dräger SC 8000 All software versions
  • Dräger SC 9000 XL All software versions

Timeline

  • 2026-06-03: advisory: NVD and VulnCheck published advisory details.

References

Related threats