VYPR
Unrated severityNVD Advisory· Published Jan 28, 2019· Updated Sep 17, 2024

CVE-2018-19012

CVE-2018-19012

Description

A privilege management vulnerability in Dräger patient monitors allows an attacker to break out of kiosk mode and gain control of the underlying operating system.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A privilege management vulnerability in Dräger patient monitors allows an attacker to break out of kiosk mode and gain control of the underlying operating system.

Vulnerability

CVE-2018-19012 is an improper privilege management vulnerability (CWE-269) in Dräger Infinity Delta, Delta XL, Kappa, and Infinity Explorer C700 patient monitors, affecting all versions. The flaw resides in the kiosk mode implementation, where a specific dialog can be exploited to escape the restricted environment and access the underlying operating system [1].

Exploitation

An attacker with physical or local access to the device can trigger the vulnerable dialog to break out of kiosk mode. The attack requires low skill and no authentication, as the dialog is accessible from the standard user interface. Once the dialog is manipulated, the attacker gains a shell or direct interaction with the operating system [1].

Impact

Successful exploitation allows the attacker to take full control of the operating system, potentially leading to arbitrary code execution, data exfiltration, or disruption of patient monitoring functions. The CVSS v3 base score is 8.4, indicating high severity [1].

Mitigation

As of the publication date of the advisory (January 2019), no specific patch or workaround is detailed in the available reference. Users are advised to contact Dräger for mitigation guidance and to monitor vendor updates [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4
  • Range: all versions
  • Dräger/Delta XLllm-create
    Range: all versions
  • Dräger/Kappallm-create
    Range: all versions
  • ICS-CERT/Dräger Infinity Deltav5
    Range: Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.