Impact
Dräger Infinity Explorer C700 suffers a privilege‑escalation flaw that lets an attacker bypass the device’s kiosk mode by interacting with a specific dialog. The vulnerability allows the attacker to exit the restricted environment and gain full control of the underlying operating system. Once compromised, the attacker can alter or conceal patient data sent to the connected Delta Family patient monitor and potentially cause the device to present no or incorrect information, jeopardizing patient safety.
Affected Systems
The flaw affects all installations of the Dräger Infinity Explorer C700. No particular firmware or hardware revision is listed, so the entire product line is considered vulnerable unless a later firmware update is applied. The product is a medical monitoring device used in clinical settings to monitor patients via Delta Family monitors.
Risk and Exploitability
The CVSS score of 8.6 labels this high severity. The EPSS score is under 1%, indicating a low probability of exploitation under current conditions, and the issue is not catalogued in CISA KEV. The likely attack vector is a local interaction with the kiosk interface: an attacker must have physical presence or authenticated access to the device to trigger the dialog that escapes kiosk mode. Based on the description, this requires that the device be accessible to the attacker; remote exploitation over a network is not documented, so the inference is that the vulnerability is constrained to local or authenticated scenarios. Exploitation would grant the attacker arbitrary system execution, enabling malicious code, data tampering, or denial of service against the patient monitoring workflow.
OpenCVE Enrichment