← All Advisories

Dräger CC-Vision crafted .gdt file triggers buffer overflow during parsing and allows crash or code execution

Last refreshed2026-09-30

Status: NEW  |  Advisory ID: CVE-2021-4478

Key Details

CVECVE-2021-4478
CVSS Score / Version8.2 (High) / CVSS v3.1
Updated2026-07-22
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is none; user interaction is required; scope is changed; confidentiality impact is none; integrity impact is high; availability impact is high.
Classified asCWE-787 (Out-of-bounds Write)

What to Know

Dräger CC-Vision Basic before 7.5.3 and Dräger CC-Vision E-Cal before 7.2.5.0 contain an out-of-bounds write vulnerability when loading .gdt files. A crafted .gdt file can trigger a buffer overflow during file parsing, allowing an attacker to crash the application or execute malicious code on the underlying system. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2021-4478
CVEhttps://www.cve.org/CVERecord?id=CVE-2021-4478