PT-2026-45864 · Dräger · Zeus Rs C500+1
CVE-2025-15653
·
Published
2026-06-02
·
Updated
2026-06-03
CVSS v3.1
6.8
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dräger Zeus Infinity Empowered (Zeus IE) (affected versions not specified)
Dräger Zeus RS C500 (affected versions not specified)
Description
A local security issue exists in anesthesia workstations that allows unauthorized individuals with physical access to compromise software integrity through the manipulation of USB interfaces. Attackers can exploit these unprotected interfaces to impair therapy functions, manipulate data processed by the device, or use the workstation as a pivot point for broader network-based attacks when the device is connected to a network or Dräger Service Connect.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zeus Infinity Empowered
Zeus Rs C500