← All Advisories

Dräger Infinity Explorer C700 kiosk escape allows OS control and causes device to display incorrect patient monitor data

Last refreshed2026-09-30

Status: UPDATED  |  Advisory ID: CVE-2019-25718

Key Details

CVECVE-2019-25718
CVSS Score / Version8.4 (High) / CVSS v3.1
Updated2026-07-22
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsdraeger infinity_explorer_c700_firmware
Classified asCWE-451 (User Interface (UI) Misrepresentation of Critical Information)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
draegerinfinity_explorer_c700_firmware
SubsystemsGeneral OT
SectorsMultiple

What to Know

Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying operating system through a specific dialog interaction. Attackers can exploit this kiosk escape to take control of the operating system and cause the device to display incorrect or no information from the connected Delta Family patient monitor. (NVD)

What to Do

Monitor draeger's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2019-25718
CVEhttps://www.cve.org/CVERecord?id=CVE-2019-25718
Vendor advisoryhttps://static.draeger.com/security/download/2019-01-22-draeger-infinity-delta-vf10-1-security-advisory.pdf