CVE-2025-15653 - CVE House
Back to Database
Status published High CVE-2025-15653

Dräger Zeus IE Anesthesia Workstation USB Interface Privilege Escalation

Vulnerability Description

Dräger Zeus Infinity Empowered (Zeus IE) and Zeus RS C500 anesthesia workstations contain a local security vulnerability that allows unauthorized individuals with physical access to compromise software integrity via USB interface manipulation. Attackers can exploit the unprotected USB interfaces to impair therapy functions, manipulate device-processed data, or leverage the device as a pivot point for broader network-based attacks when connected to a network or Dräger Service Connect.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-15653

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Zeus IE, Zeus RS C500
Vulnerable Versions:
0

Timeline

Official Publish: June 2nd, 2026
Last Modified: June 3rd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)