PT-2019-9706 · Drager · Drager Infinity Delta+3
Marc Ruef
+1
·
Published
2019-01-28
·
Updated
2019-10-09
·
CVE-2018-19014
CVSS v2.0
3.3
Low
| Vector | AV:A/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Drager Infinity Delta versions all
Drager Delta XL versions all
Drager Kappa versions all
Drager Infinity Explorer C700 versions all
Description
The issue allows log files to be accessed over an unauthenticated network connection. This access enables an attacker to gain insights into the internals of the patient monitor, its location, and the wired network configuration.
Recommendations
For Drager Infinity Delta, restrict access to log files to prevent unauthorized access.
For Drager Delta XL, limit network connections to only necessary and authenticated sources.
For Drager Kappa, consider implementing authentication for log file access.
For Drager Infinity Explorer C700, secure log files by restricting access to authorized personnel only.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Drager Delta Xl
Drager Infinity Delta
Drager Infinity Explorer C700
Drager Kappa