← All Advisories

Dräger Core and M540 malformed SDC discovery packets exhaust CPU and block further SDC message processing

Last refreshed2026-09-30

Status: NEW  |  Advisory ID: CVE-2024-14036

Key Details

CVECVE-2024-14036
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-07-22
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Classified asCWE-400 (Uncontrolled Resource Consumption)

What to Know

Dräger Core 1.0.5 and Dräger M540 Converter Service 1.0.9 contain a denial of service vulnerability that allows network-adjacent attackers to trigger high CPU load by sending specially crafted, unencrypted SDC messages during the discovery process. Attackers with access to the hospital network can send malformed SDC packets to exhaust CPU resources in the affected process, causing further SDC messages to no longer be processed. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2024-14036
CVEhttps://www.cve.org/CVERecord?id=CVE-2024-14036