Executive brief
Dräger CC-Vision is software used to manage and calibrate gas detection and respiratory protection equipment. A security flaw allows an attacker to create a malicious configuration file that, if opened by a user, could crash the software or allow the attacker to run unauthorized commands on the computer. This could disrupt safety equipment maintenance or lead to a compromise of the workstation used to manage these devices.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Dräger CC-Vision Basic (versions before 7.5.3) and CC-Vision E-Cal (versions before 7.2.5.0). The flaw is triggered during the parsing of specially crafted .gdt files, leading to a buffer overflow. An attacker can exploit this by tricking a user into loading a malicious file, potentially achieving arbitrary code execution or causing a denial-of-service (crash) on the host system. The vulnerability is local in nature and requires user interaction to trigger the file loading process. Fixes are available in CC-Vision Basic 7.5.3 and CC-Vision E-Cal 7.2.5.0.
Affected products
- Dräger CC-Vision Basic before 7.5.3
- Dräger CC-Vision E-Cal before 7.2.5.0
Timeline
- 2026-06-02: disclosed: NVD publication date