CVE Database
/

CVE-2019-25722

Back to search

CVE-2019-25722

Published: Jun 2, 2026

Modified: Jun 3, 2026

PUBLISHED

CVSS v3.1

7.6

HIGH

Description

Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain hard-coded plaintext credentials in source code and a denial-of-service vulnerability that allows local and remote attackers to compromise device integrity across all software versions. A local attacker with direct device access can use the hard-coded credentials to access service and clinical accounts and alter device configuration, while a remote attacker can send malformed network packets to cause repeated device reboots, ultimately resulting in loss of network connectivity and disruption of patient monitoring.

VendorProductVersions

Dräger

SC 6002XL

affected
SC 6002XL

Dräger

SC6802XL

affected
SC6802XL

Dräger

SC 7000

affected
SC 7000

Dräger

SC8000

affected
SC8000

Dräger

SC90000 XL

affected
SC90000 XL

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

Low

Integrity

Low

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now