Executive brief
Dräger medical networking components are vulnerable to a flaw that allows an attacker on the hospital network to disable the device's communication capabilities. By sending specifically malformed messages, an attacker can overload the system's processor, causing it to stop responding to legitimate medical data requests. This could lead to a loss of real-time monitoring or data conversion services in a clinical environment.
Technical details
A denial of service vulnerability exists in Dräger Core (<= 1.0.5) and M540 Converter Service (<= 1.0.9) due to uncontrolled resource consumption (CWE-400). The flaw is triggered during the discovery process when the service receives specially crafted, unencrypted Service-Oriented Device Connectivity (SDC) messages. An attacker with network access can transmit these malformed packets to exhaust CPU resources, effectively hanging the affected process and preventing further SDC message handling. The attack does not require authentication or user interaction.
Affected products
- Dräger Core <= 1.0.5
- Dräger M540 Converter Service <= 1.0.9
Timeline
- 2026-06-02: disclosed
- 2026-06-02: advisory