CVE-2018-19014
By accessing the log files, an attacker is able to gain insights about internals of the patient monitor, the location of the monitor, and wired network configuration.
Does this matter?
Lower severity and a low EPSS score (0.79%). Track it; it rarely justifies an emergency change on its own.
Description
Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Log files are accessible over an unauthenticated network connection. By accessing the log files, an attacker is able to gain insights about internals of the patient monitor, the location of the monitor, and wired network configuration.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.79% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-532
- Affected
- draeger/kappa firmware · draeger/infinity explorer c700 firmware · draeger/delta xl firmware · draeger/infinity delta firmware
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/106683Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSMA-19-022-01Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/106683Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSMA-19-022-01Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.