A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2019-25716

CVE-2019-25716: Dräger Patient Monitors DoS Vulnerability

CVE-2019-25716 is a denial-of-service vulnerability in Dräger Infinity Delta, Delta XL, and Kappa patient monitors. Attackers can send malformed packets to force reboots, disrupting care. This post covers technical details, impact, and mitigation.

Published: June 4, 2026

CVE-2019-25716 Overview

CVE-2019-25716 is a denial-of-service vulnerability affecting Dräger Infinity Delta, Delta XL, and Kappa patient monitors. A remote attacker on an adjacent network can send a malformed network packet that forces the monitor to reboot. Repeated transmission of the malformed packet disrupts continuous patient monitoring and eventually causes the device to fall back to its default configuration and lose network connectivity. The flaw is tracked under [CWE-15] (External Control of System or Configuration Setting) and carries a CVSS v4.0 base score of 7.1. The Exploit Prediction Scoring System (EPSS) currently rates the probability of exploitation at 0.046% (14.6th percentile).

Critical Impact

Repeated malformed packets can reboot bedside patient monitors and cut their network connectivity, interrupting clinician visibility into patient vital signs.

Affected Products

  • Dräger Infinity Delta patient monitor
  • Dräger Infinity Delta XL patient monitor
  • Dräger Infinity Kappa patient monitor

Discovery Timeline

  • 2026-06-01 - CVE-2019-25716 published to the National Vulnerability Database
  • 2026-06-03 - Last updated in the NVD database

Technical Details for CVE-2019-25716

Vulnerability Analysis

The affected Dräger Infinity Delta, Delta XL, and Kappa monitors fail to validate incoming network traffic correctly. When the device receives a specifically malformed packet, its network stack triggers an unrecoverable error condition that forces a full reboot. The reboot interrupts vital sign acquisition, alarms, and centralized monitoring data forwarded to nursing stations. An attacker who sends the malformed packet in a loop keeps the monitor in a reboot cycle. After repeated failures, the monitor reverts to its default configuration, dropping network connectivity to central monitoring infrastructure entirely. This represents a meaningful clinical safety concern in environments where continuous remote observation of patient telemetry is required.

Root Cause

The root cause is improper handling of malformed input at the network protocol layer, mapped to [CWE-15]. The device accepts and processes packets without sufficient validation, allowing attacker-controlled input to influence system state and trigger a reboot. After repeated faults, recovery logic resets device configuration to defaults rather than preserving the operational network profile.

Attack Vector

Exploitation requires adjacent network access (CVSS AV:A) to the clinical network segment carrying patient monitor traffic. No authentication or user interaction is required. An attacker positioned on the same broadcast or routed clinical VLAN can send the malformed packet directly to the monitor. The attack does not affect confidentiality or integrity; the impact is limited to availability (VA:H), but the operational consequence in a hospital environment is significant.

No public proof-of-concept exploit code is available, and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog. For protocol-level details, refer to the Dräger Security Advisory and the VulnCheck Security Advisory.

Detection Methods for CVE-2019-25716

Indicators of Compromise

  • Unscheduled reboots of Dräger Infinity Delta, Delta XL, or Kappa monitors during clinical operations.
  • Patient monitors reverting to default network configuration and losing connectivity to central monitoring servers.
  • Repeated link-state or DHCP renewal events originating from monitor MAC addresses on clinical VLANs.

Detection Strategies

  • Inspect biomedical network segments for anomalous or malformed packets directed at known patient monitor IP addresses.
  • Correlate device reboot events from the central monitoring system with network telemetry captured at clinical switches.
  • Alert on unexpected ARP, DHCP, or link-up events from monitor MAC address ranges, which often follow a forced reboot.

Monitoring Recommendations

  • Forward switch, firewall, and biomedical gateway logs into a centralized analytics platform for cross-correlation with monitor uptime data.
  • Establish a baseline of normal traffic volumes and protocols for the monitoring VLAN and alert on deviations.
  • Use medical-device-aware network monitoring tools that can fingerprint Dräger Infinity devices and flag protocol anomalies.

How to Mitigate CVE-2019-25716

Immediate Actions Required

  • Place all Dräger Infinity Delta, Delta XL, and Kappa monitors on an isolated clinical VLAN with strict access control lists.
  • Restrict layer-2 and layer-3 reachability so only authorized central monitoring servers and biomedical engineering workstations can communicate with the monitors.
  • Contact Dräger support to confirm device firmware status and obtain remediation guidance specific to the deployed version.

Patch Information

Dräger has published vendor remediation guidance in the Dräger Security Advisory. Operators should coordinate with Dräger service representatives to apply the recommended software update or configuration change for affected Infinity Delta VF10.1 and related Kappa devices, as field updates to medical equipment require qualified biomedical engineering involvement.

Workarounds

  • Segment patient monitors behind a dedicated firewall that drops malformed or unexpected protocols at the perimeter of the monitoring VLAN.
  • Disable or block unused network services on the monitor and enforce static ARP entries on the upstream switch to limit spoofing.
  • Implement port security and 802.1X on access switches so unauthorized devices cannot join the clinical monitoring segment.
bash
# Example switch ACL restricting traffic to authorized central monitoring server only
interface GigabitEthernet0/12
 description Draeger Infinity Delta monitor
 switchport access vlan 50
 switchport port-security maximum 1
 switchport port-security violation restrict
 ip access-group MONITOR-IN in
!
ip access-list extended MONITOR-IN
 permit ip host 10.50.10.20 host 10.50.1.5
 deny   ip any any log

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeDOS

  • Vendor/TechDräger

  • SeverityHIGH

  • CVSS Score7.1

  • EPSS Probability0.05%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-15
  • Technical References
  • Draeger Security Advisory

  • VulnCheck Security Advisory
  • Related CVEs
  • CVE-2019-25720: Dräger SC Monitoring DOS Vulnerability

  • CVE-2019-25718: Dräger Infinity Explorer C700 Vulnerability

  • CVE-2019-25717: Dräger Patient Monitor Info Disclosure
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English