PT-2019-9706 · Drager · Drager Infinity Delta+3
Marc Ruef
+1
·
Publicado
2019-01-28
·
Atualizado
2019-10-09
·
CVE-2018-19014
CVSS v2.0
3.3
Baixa
| Vetor | AV:A/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Drager Infinity Delta versions all
Drager Delta XL versions all
Drager Kappa versions all
Drager Infinity Explorer C700 versions all
Description
The issue allows log files to be accessed over an unauthenticated network connection. This access enables an attacker to gain insights into the internals of the patient monitor, its location, and the wired network configuration.
Recommendations
For Drager Infinity Delta, restrict access to log files to prevent unauthorized access.
For Drager Delta XL, limit network connections to only necessary and authenticated sources.
For Drager Kappa, consider implementing authentication for log file access.
For Drager Infinity Explorer C700, secure log files by restricting access to authorized personnel only.
Correção
Insertion into Log File
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Drager Delta Xl
Drager Infinity Delta
Drager Infinity Explorer C700
Drager Kappa