CVE Feed

    Dashboard / CVE / CVE-2019-25722

    CVE-2019-25722

    Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain hard-coded plaintext credentials in source code and a denial-of-service vulnerability that allows local and remote attackers to compromise device integrity across all software versions. A local attacker with direct device access can use the hard-coded credentials to access service and clinical accounts and alter device configuration, while a remote attacker can send malformed network packets to cause repeated device reboots, ultimately resulting in loss of network connectivity and disruption of patient monitoring.

    Published:Jun 2, 2026
    Last Modified:Jun 3, 2026
    EPS:Jun 2, 2026
    EPSS Score:0.00043
    CVSS Score:7.6

    Affected Products

    Vendor
    Draeger
    Product
    Sc6802xl
    Vendor
    Draeger
    Product
    Sc8000
    Vendor
    Draeger
    Product
    Sc90000 Xl
    Vendor
    Draeger
    Product
    Sc 6002xl
    Vendor
    Draeger
    Product
    Sc 7000

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High