Junglewise Threat Intelligence

CVE-2019-25723: Dräger Perseus A500 improper input handling in Medibus interface

CVE-2019-25723 · Severity: medium · CVSS 4 · Published 2026-06-02

Vendors: Dräger.

Executive brief

The Dräger Perseus A500 is an anesthesia workstation used to provide ventilation and anesthesia to patients during medical procedures. A vulnerability in its communication interface allows an attacker to send malformed data that crashes the device's internal processor. This causes a temporary loss of ventilation pressure and interrupts patient therapy for several seconds while the system restarts, potentially impacting patient safety.

Technical details

An improper input handling vulnerability (CWE-1286) exists in the Medibus interface of Dräger Perseus A500 anesthesia workstations running software versions 2.00 to 2.02. An unauthenticated attacker with network access to the Medibus interface can transmit specially crafted, non-compliant data packets to the device. This malformed input overloads the internal processor, triggering a warm restart of the system. During this restart period, ventilation pressure drops to ambient levels, resulting in a temporary cessation of therapy for several seconds until the system automatically resumes operation. The attack requires the ability to reach the Medibus interface, which is typically used for medical device data integration.

Affected products

  • Dräger Perseus A500 2.00 through 2.02

Timeline

  • 2026-06-02: advisory: Vulnerability published by VulnCheck and NVD.

References