CVE-2025-15653
Received Received - Intake
Dräger Zeus Infinity Empowered USB Interface Security Bypass

Publication date: 2026-06-02

Last updated on: 2026-06-02

Assigner: VulnCheck

Description
Dräger Zeus Infinity Empowered (Zeus IE) and Zeus RS C500 anesthesia workstations contain a local security vulnerability that allows unauthorized individuals with physical access to compromise software integrity via USB interface manipulation. Attackers can exploit the unprotected USB interfaces to impair therapy functions, manipulate device-processed data, or leverage the device as a pivot point for broader network-based attacks when connected to a network or Dräger Service Connect.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-02
Last Modified
2026-06-02
Generated
2026-06-03
AI Q&A
2026-06-03
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
dräger zeus_infinity_empowered *
dräger zeus_rs_c500 *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-668 The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability affects Dräger Zeus Infinity Empowered (Zeus IE) and Zeus RS C500 anesthesia workstations. It is a local security issue that allows unauthorized individuals who have physical access to the device to compromise its software integrity by manipulating the USB interfaces. Because the USB interfaces are unprotected, attackers can exploit them to interfere with therapy functions, alter data processed by the device, or use the device as a pivot point to launch broader network attacks if the device is connected to a network or Dräger Service Connect.


How can this vulnerability impact me? :

The impact of this vulnerability includes the potential impairment of therapy functions provided by the anesthesia workstations, manipulation of critical device-processed data, and the risk of the device being used as a pivot point for further network-based attacks. This could lead to compromised patient care, incorrect medical data, and broader security breaches within connected healthcare networks.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart