Junglewise Threat Intelligence

CVE-2021-4479: Dräger Atlan A350 denial of service in Medibus interface

CVE-2021-4479 · Severity: medium · CVSS 4 · Published 2026-06-02

Vendors: Dräger.

Executive brief

The Dräger Atlan A350, an anesthesia workstation used in clinical settings, contains a vulnerability in its data communication interface. An attacker can send specially crafted data to the device, causing its internal processor to become overloaded. Over several hours, this can lead to delayed display of vital patient information, such as real-time pressure curves, and a loss of data transmission, potentially impacting clinical decision-making.

Technical details

An improper input handling vulnerability (CWE-1286) exists in the Medibus interface of Dräger Atlan A350 anesthesia workstations running software versions 1.00 to 1.01. By transmitting malformed, non-compliant Medibus data over the network, an attacker can cause an internal processor overload. This is a slow-acting denial-of-service attack that gradually disrupts device operations over several hours. Impacted functions include the loss of data transmission to external systems, significant delays in the display of real-time curves, and discrepancies between actual airway pressure values and the visual representations on the screen. The attack requires network access to the Medibus interface but no authentication.

Affected products

  • Dräger Atlan A350 1.00 through 1.01

Timeline

  • 2026-06-02: disclosed
  • 2026-06-02: advisory

References