Junglewise Threat Intelligence

CVE-2021-4478: Dräger CC-Vision out-of-bounds write in .gdt file parsing

CVE-2021-4478 · Severity: high · CVSS 8.2 · Published 2026-06-02

Vendors: Dräger.

Executive brief

Dräger CC-Vision is software used to manage and calibrate gas detection and respiratory protection equipment. A security flaw allows an attacker to create a malicious configuration file that, if opened by a user, could crash the software or allow the attacker to run unauthorized commands on the computer. This could disrupt safety equipment maintenance or lead to a compromise of the workstation used to manage these devices.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in Dräger CC-Vision Basic (versions before 7.5.3) and CC-Vision E-Cal (versions before 7.2.5.0). The flaw is triggered during the parsing of specially crafted .gdt files, leading to a buffer overflow. An attacker can exploit this by tricking a user into loading a malicious file, potentially achieving arbitrary code execution or causing a denial-of-service (crash) on the host system. The vulnerability is local in nature and requires user interaction to trigger the file loading process. Fixes are available in CC-Vision Basic 7.5.3 and CC-Vision E-Cal 7.2.5.0.

Affected products

  • Dräger CC-Vision Basic before 7.5.3
  • Dräger CC-Vision E-Cal before 7.2.5.0

Timeline

  • 2026-06-02: disclosed: NVD publication date

References