Description
Draeger X-Dock Firmware before 03.00.13 has Hard-Coded Credentials, leading to remote code execution by an authenticated attacker.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_misc
https://static.draeger.com/security
Vendor Advisory x_refsource_confirm
https://static.draeger.com/security/download/PSA-21-120-1-X-Dock-Product-Security-Advisory.pdf
Third Party Advisory, VDB Entry x_refsource_misc
https://www.zerodayinitiative.com/advisories/ZDI-21-604/
Scores
CVSS v3
8.8
EPSS
0.0310
EPSS Percentile
86.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-798
Status
published
Products (1)
draeger/x-dock_firmware
< 03.00.13
Published
May 20, 2021
Tracked Since
Feb 18, 2026