Executive brief
Dräger SC Monitoring devices, which are used in clinical settings to monitor patient health, contain hard-coded passwords and a flaw that allows for service disruption. An attacker could use these fixed passwords to gain administrative access and change device settings, or send malicious network traffic to force the device to reboot repeatedly. This could lead to a total loss of patient monitoring capabilities, potentially delaying medical intervention or impacting patient safety.
Technical details
The vulnerability consists of two primary issues within Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL). First, hard-coded plaintext credentials (CWE-798) exist in the source code, allowing an attacker with local or adjacent network access to authenticate to service and clinical accounts and modify device configurations. Second, the devices are susceptible to a denial-of-service attack where malformed network packets trigger repeated reboots. These vulnerabilities affect all software versions and can be exploited without user interaction, resulting in a complete loss of availability for patient monitoring services.
Affected products
- Dräger SC 6002XL All versions
- Dräger SC 6802XL All versions
- Dräger SC 7000 All versions
- Dräger SC 8000 All versions
- Dräger SC 9000 XL All versions
Timeline
- 2026-06-02: disclosed: Vulnerability published in NVD dataset via VulnCheck.