Description
Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain a denial-of-service vulnerability in all software versions that allows unauthenticated attackers to reboot the monitor by sending a malformed network packet. Attackers can repeatedly send such malformed packets to disrupt patient monitoring until the device falls back to default configuration and loses network connectivity.
Problem types
CWE-1286 Improper Validation of Syntactic Correctness of Input
Product status
SC 6002XL (custom)
SC6802XL (custom)
SC 7000 (custom)
SC8000 (custom)
SC90000 XL (custom)
Credits
Jeroen Slobbe and Max Grim
References
static.draeger.com/…9000-security-advisory-update-v1-5.pdf
www.vulncheck.com/…evices-dos-via-malformed-network-packet
