CVE-2024-14036 PUBLISHED

Dräger Core 1.0.5 Denial of Service via Malformed SDC Message

Assigner: VulnCheck
Reserved: 02.06.2026 Published: 02.06.2026 Updated: 03.06.2026

Dräger Core 1.0.5 and Dräger M540 Converter Service 1.0.9 contain a denial of service vulnerability that allows network-adjacent attackers to trigger high CPU load by sending specially crafted, unencrypted SDC messages during the discovery process. Attackers with access to the hospital network can send malformed SDC packets to exhaust CPU resources in the affected process, causing further SDC messages to no longer be processed.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Dräger
Product Core
Versions Default: unknown
  • affected from 0 to 1.0.5 (excl.)
Vendor Dräger
Product M540 Converter Service
Versions Default: unknown
  • affected from 0 to 1.0.9 (excl.)

References

Problem Types

  • CWE-400 Uncontrolled Resource Consumption CWE