Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated network attackers to access log files over a network connection. Attackers can retrieve device internals, location information, and wired network configuration details from the exposed log files.
References
| Link | Resource |
|---|---|
| https://static.draeger.com/security | Vendor Advisory |
| https://www.vulncheck.com/advisories/dr-ger-infinity-delta-kappa-patient-monitors-unauthenticated-log-file-disclosure | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
History
30 Jun 2026, 19:02
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://static.draeger.com/security - Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/dr-ger-infinity-delta-kappa-patient-monitors-unauthenticated-log-file-disclosure - Third Party Advisory, VDB Entry | |
| First Time |
Draeger kappa Firmware
Draeger kappa Draeger delta Xl Draeger Draeger infinity Delta Draeger delta Xl Firmware Draeger infinity Delta Firmware |
|
| CPE | cpe:2.3:o:draeger:delta_xl_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:draeger:kappa:-:*:*:*:*:*:*:* cpe:2.3:h:draeger:infinity_delta:-:*:*:*:*:*:*:* cpe:2.3:o:draeger:infinity_delta_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:draeger:kappa_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:draeger:delta_xl:-:*:*:*:*:*:*:* |
|
| CWE | NVD-CWE-noinfo |
02 Jun 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-02 14:16
Updated : 2026-06-30 19:02
NVD link : CVE-2019-25717
Mitre link : CVE-2019-25717
CVE.ORG link : CVE-2019-25717
JSON object : View
Products Affected
draeger
- infinity_delta_firmware
- kappa_firmware
- delta_xl_firmware
- delta_xl
- infinity_delta
- kappa
CWE
CWE-538
Insertion of Sensitive Information into Externally-Accessible File or Directory
NVD-CWE-noinfo