Executive brief
Dräger Zeus anesthesia workstations, used in surgical environments to deliver anesthesia and monitor patients, contain a security flaw in their physical USB ports. An unauthorized person with physical access to the device could use these ports to interfere with medical therapy, alter patient data, or use the workstation as a gateway to attack the hospital's internal network. This could lead to life-critical equipment failure or the compromise of sensitive medical information.
Technical details
The Dräger Zeus IE and Zeus RS C500 anesthesia workstations suffer from an exposure of resource to wrong sphere (CWE-668) due to unprotected USB interfaces. An attacker with physical access can manipulate these interfaces to compromise software integrity without requiring prior authentication. Successful exploitation allows an attacker to impair therapy functions, manipulate device-processed data, or utilize the workstation as a pivot point for lateral movement within the connected hospital network or Dräger Service Connect. The vulnerability affects all versions of the Zeus IE and Zeus RS C500 models.
Affected products
- Dräger Zeus Infinity Empowered (Zeus IE) All versions
- Dräger Zeus RS C500 All versions
Timeline
- 2026-06-02: advisory: Vulnerability disclosed by VulnCheck and NVD