PT-2026-45864 · Dräger · Zeus Rs C500+1

CVE-2025-15653

·

Published

2026-06-02

·

Updated

2026-06-03

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dräger Zeus Infinity Empowered (Zeus IE) (affected versions not specified) Dräger Zeus RS C500 (affected versions not specified)
Description A local security issue exists in anesthesia workstations that allows unauthorized individuals with physical access to compromise software integrity through the manipulation of USB interfaces. Attackers can exploit these unprotected interfaces to impair therapy functions, manipulate data processed by the device, or use the workstation as a pivot point for broader network-based attacks when the device is connected to a network or Dräger Service Connect.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-15653

Affected Products

Zeus Infinity Empowered
Zeus Rs C500