CVE-2024-14036

Dräger Core 1.0.5 and Dräger M540 Converter Service 1.0.9 contain a denial of service vulnerability that allows network-adjacent attackers to trigger high CPU load by sending specially crafted, unencrypted SDC messages during the discovery process. Attackers with access to the hospital network can send malformed SDC packets to exhaust CPU resources in the affected process, causing further SDC messages to no longer be processed.
Configurations

No configuration.

History

03 Jun 2026, 20:16

Type Values Removed Values Added
References
  • {'url': 'https://static.draeger.com/security', 'source': 'disclosure@vulncheck.com'}
  • () https://static.draeger.com/security/download/PSA-24-110-1-gSOAP-Product-Security-Advisory.pdf -

02 Jun 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-02 22:16

Updated : 2026-06-04 15:29


NVD link : CVE-2024-14036

Mitre link : CVE-2024-14036

CVE.ORG link : CVE-2024-14036


JSON object : View

Products Affected

No product.

CWE
CWE-400

Uncontrolled Resource Consumption