Draeger X-Dock Firmware before 03.00.13 has Hard-Coded Credentials, leading to remote code execution by an authenticated attacker.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDraeger X Dock 5300
HWDraegerall versionsDraeger X Dock 6300
HWDraegerall versionsDraeger X Dock 6600
HWDraegerall versionsDraeger X Dock Firmware
OSDraeger< 03.00.13
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCE
CWE
Related vulnerabilities
CVE-2021-28112HIGH8.8same product
Draeger X-Dock Firmware before 03.00.13 has Active Debug Code on a debug port, leading to remote code executio...
CVE-2019-25716HIGH7.1same vendor
Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service vulnerability that all...
CVE-2019-25718HIGH8.6same vendor
Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out...
CVE-2018-19012HIGH7.8same vendor
Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity ...
CVE-2019-25717MEDIUM5.3same vendor
Urządzenia monitorujące pacjentów Dräger Infinity Delta, Delta XL i Kappa zawierają lukę information disclosur...