VDE-2025-028
Last update
01/06/2026 12:00
Published at
08/05/2025 12:00
Vendor(s)
CERT@VDE
External ID
VDE-2025-028
CSAF Document
Summary
A security vulnerability was identified in the ICMHelper service running on the system of an ICM installation.
A low privileged local attacker could exploit this vulnerability to issue OS commands with the highest privileges.
Impact
The vulnerability CVE-2025-41698 allows an attacker to gain full access to application, sensitive information, client system and server. This requires successful exploitation of CVE-2025-2810.
Affected Product(s)
| Model no. | Product name | Affected versions |
|---|---|---|
| Draeger ICMHelper <=1.4.0.1 | Draeger ICMHelper <=1.4.0.1 |
Vulnerabilities
Expand / Collapse allRemediation
The issue has been fixed in ICMHelper version 2.0.1.0.
Acknowledgments
CERT@VDE thanks the following parties for their efforts:
- CERT@VDE for coordination (see https://certvde.com )
- CODE WHITE GmbH for responsible disclosure
Revision History
| Version | Date | Summary |
|---|---|---|
| 1.0.0 | 08/05/2025 12:00 | Initial revision. |
| 2.0.0 | 12/15/2025 12:00 | Changes to publisher Added CPEs as product_identification_helper |
| 3.0.0 | 01/06/2026 12:00 | fixed version range, fixed Aggregate severity, changed vulnerability Title to CVE description, fix CPE to have at least one for affected products |