s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVE-2019-25717

📛 CVE Title

(no title)

Description

Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated network attackers to access log files over a network connection. Attackers can retrieve device internals, location information, and wired network configuration details from the exposed log files.

Overview

State
—
Assigner (CNA)
—
CVSS severity
medium
CVSS score
CVSS 4.3 / 10 4.3 4.3 / 10
CVSS vector
AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Effective score
4.3 / 10 MEDIUM source: CNA overview
CWE(s)
—
Reserved
—
Published
—
Last updated
—
Source
https://www.tenable.com/cve/CVE-2019-25717

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2026-06-02 14:16:24 UTC
NVD last modified
2026-07-22 19:10:00 UTC
NVD CVSS v3.1
CVSS 4.3 / 10 4.3 4.3 / 10 MEDIUM source: disclosure@vulncheck.com
NVD CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability subscore
2.8 / 10
Impact subscore
1.4 / 10
EPSS score
0.0020 (probability of exploitation in next 30 days)
EPSS percentile
10.45% vs all CVEs — higher = more likely to be exploited, as of 2026-08-01

NVD-assigned CWE(s): CWE-538 (differs from the CNA list above)

NVD / KEV / EPSS data refreshed 2026-08-01 16:28 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2019-20155
Assigner
VulnCheck
Published
Jun 2, 2026, 1:42:35 PM
Updated
Jul 15, 2026, 1:24:11 AM
EUVD base score (CVSS 4.0)
5.3 / 10
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
EUVD-reported EPSS
0.2000
Vendors
Dräger
Products
Infinity Delta XL (all software versions)
Infinity Kappa (all software versions)
Infinity Delta (all software versions)
Aliases
GHSA-pch2-3675-w238

ENISA description: Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated network attackers to access log files over a network connection. Attackers can retrieve device internals, location information, and wired network configuration details from the exposed log files.

EUVD references (2)

Affected products — CPE 2.3 (6) NVD

NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.

  • cpe:2.3:o:draeger:infinity_delta_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:draeger:infinity_delta:-:*:*:*:*:*:*:*
  • cpe:2.3:o:draeger:delta_xl_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:draeger:delta_xl:-:*:*:*:*:*:*:*
  • cpe:2.3:o:draeger:kappa_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:draeger:kappa:-:*:*:*:*:*:*:*

Vendor references (0)

References embedded in the original CVE record by the assigning CNA.

None in the CVE record.

Web references (5)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

NVD-tagged references (2)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Remediations (10)

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2019-25717.json.

Not stored.