← Vulnerability feed

Vulnerability record · CVE-2019-25716 · published 1 June 2026

CVE-2019-25716: Draeger infinity delta firmware vulnerability

Draeger · Infinity Delta Firmware

Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service vulnerability that allows remote attackers to cause the monitor to reboot by sending a malformed network packet. Attackers can repeatedly send malformed network packets to disrupt patient monitoring until the device falls back to default configuration and loses network connectivity.

7.1 CVSS 4.0 High EPSS 0.41% · top 66.9% CWE-15 · CWE-15
7.1CVSS 4.0 base score
0.41%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
2References
22 Jul 2026Last modified by NVD

Description

Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service vulnerability that allows remote attackers to cause the monitor to reboot by sending a malformed network packet. Attackers can repeatedly send malformed network packets to disrupt patient monitoring until the device falls back to default configuration and loses network connectivity.

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-25716 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2018-19012Draeger kappa firmware improper privilege management vulnerabilityDrager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Via a spec…EPSS 0.39%6.5CVE-2018-19010Draeger kappa firmware improper input validation vulnerabilityDrager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. A malforme…EPSS 0.77%6.5CVE-2018-19014Draeger kappa firmware sensitive information in log file vulnerabilityDrager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Log files …EPSS 0.79%5.3CVE-2019-25717Draeger infinity delta firmware vulnerabilityDräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated network attac…EPSS 0.20%8.8CVE-2009-1537Microsoft DirectShow QuickTime Parser NULL Byte Overwrite RCEThe QuickTime Movie Parser Filter in quartz.dll (DirectShow, DirectX 7.0 through 9.0c) contains an unspecified NULL byte overwrite flaw. A crafted Qu…KEVEPSS 51%analysed10.0CVE-2025-47812Wing FTP Server null byte handling leads to Lua code injection RCEWing FTP Server before 7.4.4 mishandles '\0' bytes in its user and admin web interfaces, allowing injection of arbitrary Lua code into user session f…KEVEPSS 93%analysed

Source: NIST National Vulnerability Database (record CVE-2019-25716), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.