CVE-2021-4478
Awaiting Analysis Awaiting Analysis - Queue
Out-of-Bounds Write in Dräger CC-Vision Basic and E-Cal

Publication date: 2026-06-02

Last updated on: 2026-06-03

Assigner: VulnCheck

Description
Dräger CC-Vision Basic before 7.5.3 and Dräger CC-Vision E-Cal before 7.2.5.0 contain an out-of-bounds write vulnerability when loading .gdt files. A crafted .gdt file can trigger a buffer overflow during file parsing, allowing an attacker to crash the application or execute malicious code on the underlying system.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-02
Last Modified
2026-06-03
Generated
2026-06-23
AI Q&A
2026-06-03
EPSS Evaluated
2026-06-21
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
dräger cc-vision_basic to 7.5.3 (exc)
dräger cc-vision_e-cal to 7.2.5.0 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Detection Guidance

This vulnerability is triggered by processing malicious .gdt files in Dräger CC-Vision Basic and Dräger CC-Vision E-Cal applications. Detection involves identifying the presence of vulnerable versions of these applications and monitoring for suspicious .gdt file activity.

Since the vulnerability occurs during file parsing, you can detect it by checking the version of the installed software to confirm if it is before 7.5.3 for CC-Vision Basic or before 7.2.5.0 for CC-Vision E-Cal.

There are no specific commands provided in the resources to detect exploitation attempts or scan for malicious .gdt files.

Executive Summary

This vulnerability exists in Dräger CC-Vision Basic versions before 7.5.3 and Dräger CC-Vision E-Cal versions before 7.2.5.0. It is caused by an out-of-bounds write when loading .gdt files. Specifically, a specially crafted .gdt file can trigger a buffer overflow during the file parsing process.

This buffer overflow can allow an attacker to either crash the application or execute malicious code on the underlying system.

Impact Analysis

The impact of this vulnerability includes the potential for an attacker to crash the affected application, causing denial of service.

More seriously, the attacker may be able to execute arbitrary malicious code on the underlying system, which could lead to unauthorized control, data manipulation, or further compromise of the system.

Mitigation Strategies

The primary mitigation step is to upgrade Dräger CC-Vision Basic to version 7.5.3 or later, and Dräger CC-Vision E-Cal to version 7.2.5.0 or later, as these versions contain fixes for the out-of-bounds write vulnerability.

Until the upgrade can be applied, avoid opening or processing untrusted or suspicious .gdt files to prevent triggering the buffer overflow.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2021-4478. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart