Denial of Service Vulnerability in Dräger Core and M540 Converter Service
CVE-2024-14036

8.7HIGH

Key Information:

Vendor

Dräger

Vendor
CVE Published:
2 June 2026

What is CVE-2024-14036?

The Dräger Core 1.0.5 and Dräger M540 Converter Service 1.0.9 are susceptible to a denial of service vulnerability that enables network-adjacent attackers to induce excessive CPU load. This is executed by sending crafted, unencrypted SDC messages during the discovery phase. Attackers on the hospital network can exploit this flaw by dispatching malformed SDC packets, which can lead to resource exhaustion, preventing the process from handling subsequent SDC messages effectively.

Affected Version(s)

Core 0 < 1.0.5

M540 Converter Service 0 < 1.0.9

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.