Description
Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying operating system through a specific dialog interaction. Attackers can exploit this kiosk escape to take control of the operating system and cause the device to display incorrect or no information from the connected Delta Family patient monitor.
Published: 2026-06-01
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dräger Infinity Explorer C700 suffers a privilege‑escalation flaw that lets an attacker bypass the device’s kiosk mode by interacting with a specific dialog. The vulnerability allows the attacker to exit the restricted environment and gain full control of the underlying operating system. Once compromised, the attacker can alter or conceal patient data sent to the connected Delta Family patient monitor and potentially cause the device to present no or incorrect information, jeopardizing patient safety.

Affected Systems

The flaw affects all installations of the Dräger Infinity Explorer C700. No particular firmware or hardware revision is listed, so the entire product line is considered vulnerable unless a later firmware update is applied. The product is a medical monitoring device used in clinical settings to monitor patients via Delta Family monitors.

Risk and Exploitability

The CVSS score of 8.6 labels this high severity. The EPSS score is under 1%, indicating a low probability of exploitation under current conditions, and the issue is not catalogued in CISA KEV. The likely attack vector is a local interaction with the kiosk interface: an attacker must have physical presence or authenticated access to the device to trigger the dialog that escapes kiosk mode. Based on the description, this requires that the device be accessible to the attacker; remote exploitation over a network is not documented, so the inference is that the vulnerability is constrained to local or authenticated scenarios. Exploitation would grant the attacker arbitrary system execution, enabling malicious code, data tampering, or denial of service against the patient monitoring workflow.

Generated by OpenCVE AI on August 12, 2026 at 02:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the latest firmware update or patch released by Dräger that addresses the kiosk mode bypass.
  • Disable the dialog that allows kiosk mode escape or enforce stricter kiosk mode by resetting the device to factory settings and reconfiguring the kiosk interface to lock the escape path, ensuring configuration changes are authorized and validated to mitigate CWE‑451.
  • Restrict physical access to the device to authorized personnel and monitor for suspicious interactions with the kiosk dialog to detect potential exploitation attempts.

Generated by OpenCVE AI on August 12, 2026 at 02:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:h:draeger:infinity_explorer_c700:infinity_explorer_c700:*:*:*:*:*:*:*

Wed, 03 Jun 2026 22:30:00 +0000

Type Values Removed Values Added
References

Wed, 03 Jun 2026 21:30:00 +0000


Tue, 02 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 02 Jun 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Draeger
Draeger infinity Explorer C700
Vendors & Products Draeger
Draeger infinity Explorer C700

Mon, 01 Jun 2026 22:30:00 +0000

Type Values Removed Values Added
Description Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying operating system through a specific dialog interaction. Attackers can exploit this kiosk escape to take control of the operating system and cause the device to display incorrect or no information from the connected Delta Family patient monitor.
Title Dräger Infinity Explorer C700 Privilege Escalation via Kiosk Mode Bypass
Weaknesses CWE-451
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Draeger Infinity Explorer C700 Infinity Explorer C700 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-15T01:24:11.790Z

Reserved: 2026-06-01T21:36:41.544Z

Link: CVE-2019-25718

cve-icon Vulnrichment

Updated: 2026-06-02T12:28:59.427Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-01T23:16:13.270

Modified: 2026-07-22T18:10:00.117

Link: CVE-2019-25718

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T03:00:11Z

Weaknesses