CVE-2019-25716
📛 CVE Title
(no title)
Description
Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service vulnerability that allows remote attackers to cause the monitor to reboot by sending a malformed network packet. Attackers can repeatedly send malformed network packets to disrupt patient monitoring until the device falls back to default configuration and loses network connectivity.
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- medium
- CVSS score
- 6.5 / 10
- CVSS vector
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H- Effective score
- 6.5 / 10 MEDIUM source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- —
- Last updated
- —
- Source
- https://www.tenable.com/cve/CVE-2019-25716
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-06-01 22:16:17 UTC
- NVD last modified
- 2026-07-22 08:10:00 UTC
- NVD CVSS v3.1
- 6.5 / 10 MEDIUM source: disclosure@vulncheck.com
- NVD CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H- Exploitability subscore
- 2.8 / 10
- Impact subscore
- 3.6 / 10
- EPSS score
- 0.0041 (probability of exploitation in next 30 days)
- EPSS percentile
- 34.05% vs all CVEs — higher = more likely to be exploited, as of 2026-08-01
NVD-assigned CWE(s):
CWE-15
(differs from the CNA list above)
NVD / KEV / EPSS data refreshed 2026-08-01 16:28 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2019-20153 - Assigner
- VulnCheck
- Published
- Jun 1, 2026, 9:15:07 PM
- Updated
- Jul 15, 2026, 1:24:10 AM
- EUVD base score (CVSS 4.0)
-
7.1 / 10
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N - EUVD-reported EPSS
- 0.4100
- Vendors
- Dräger
- Products
-
Infinity Delta XL (Infinity Delta XL)Infinity Delta (Infinity Delta)Infinity Kappa (Infinity Kappa)
- Aliases
-
GHSA-x6h5-p8qf-9j76
ENISA description: Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service vulnerability that allows remote attackers to cause the monitor to reboot by sending a malformed network packet. Attackers can repeatedly send malformed network packets to disrupt patient monitoring until the device falls back to default configuration and loses network connectivity.
Affected products — CPE 2.3 (6) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:o:draeger:infinity_delta_firmware:*:*:*:*:*:*:*:*cpe:2.3:h:draeger:infinity_delta:-:*:*:*:*:*:*:*cpe:2.3:o:draeger:delta_xl_firmware:*:*:*:*:*:*:*:*cpe:2.3:h:draeger:delta_xl:-:*:*:*:*:*:*:*cpe:2.3:o:draeger:kappa_firmware:*:*:*:*:*:*:*:*cpe:2.3:h:draeger:kappa:-:*:*:*:*:*:*:*
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (5)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://nvd.nist.gov/vuln/detail/CVE-2019-25716 tenable:nvd.nist.gov
- https://static.draeger.com/security/download/2019-01-22-draeger-infinity-delta-vf10-1-security-advisory.pdf tenable:static.draeger.com
- https://www.cve.org/CVERecord?id=CVE-2019-25716 tenable:www.cve.org
- https://www.first.org/epss/ tenable:www.first.org
- https://www.vulncheck.com/advisories/dr-ger-infinity-delta-kappa-patient-monitor-dos-via-malformed-network-packet tenable:www.vulncheck.com
NVD-tagged references (2)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://static.draeger.com/security/download/2019-01-22-draeger-infinity-delta-vf10-1-security-advisory.pdf disclosure@vulncheck.com Vendor Advisory
- https://www.vulncheck.com/advisories/dr-ger-infinity-delta-kappa-patient-monitor-dos-via-malformed-network-packet disclosure@vulncheck.com Third Party AdvisoryVDB Entry
Remediations (10)
-
web:blog.qualys.com
Key Takeaways RedSun is a critical zero-day vulnerability in Microsoft Defender that allows low-privileged users to gain SYSTEM access No patch is currently available, leaving all Defender-enabled Windows systems potentially exposed Qualys VMDR detects affected assets instantly (QID 92382) TruRisk™ Eliminate enables immediate mitigation , removing exploitability without waiting for a fix ...
2026-06-19 02:55 UTC -
web:cybersecuritynews.com
Microsoft has officially acknowledged a critical zero-day vulnerability in Microsoft Defender, publicly dubbed "RoguePlanet," and confirmed it is actively developing a security patch to address the flaw.
2026-06-19 02:55 UTC -
web:cybersecuritynews.com
Microsoft's May 2026 Patch Tuesday lands with a heavy enterprise focus, fixing 120 vulnerabilities across Windows, Office, Azure, developer tools, and Microsoft 365 apps, including 29 remote code execution (RCE) flaws rated Critical.
2026-06-19 02:55 UTC -
web:nvd.nist.gov
An official website of the United States government Here's how you know
2026-06-19 02:55 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-06-19 02:55 UTC -
web:support.microsoft.com
Applies to: Windows Server 2019 This security update includes fixes and quality improvements that are part of the following update: May 12, 2026—KB5087538 (OS Build 17763.8755) The following is a summary of the issues that this update addresses when you install this update. The bold text within the brackets indicates the item or area of the change we are documenting. [Secure Boot] This ...
2026-06-19 02:55 UTC -
web:www.bleepingcomputer.com
Today is Microsoft's September 2025 Patch Tuesday, which includes security updates for 81 flaws, including two publicly disclosed zero-day vulnerabilities.
2026-06-19 02:55 UTC -
web:www.bleepingcomputer.com
CISA has ordered U.S. federal agencies to patch a Microsoft Defender privilege escalation flaw (dubbed BlueHammer) that has been exploited in zero-day attacks.
2026-06-19 02:55 UTC -
web:www.linkedin.com
Microsoft has confirmed that it is developing a security update to address a newly disclosed zero-day vulnerability in Microsoft Defender, following the public release of exploit code that ...
2026-06-19 02:55 UTC -
web:www.malwarebytes.com
Microsoft says it's working on a fix for an unpatched Defender vulnerability that can give attackers the highest level of access on Windows.
2026-06-19 02:55 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.