Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors versions VG4.1.1, VG4.0.3, and lower (with VG4.2 partially affected) contain a network message handling vulnerability that allows remote attackers to inject spoofed or tampered data and cause denial-of-service conditions. Attackers can compromise network communications to modify device settings such as alarm states or alarm limits, or overwhelm the system with excessive network traffic causing the Cockpit or M540 to reboot and lose network functionality.
Metrics
Affected Vendors & Products
References
History
Wed, 03 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 03 Jun 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Draeger
Draeger infinity Acute Care System Draeger standalone Infinity M540 Patient Monitor |
|
| Vendors & Products |
Draeger
Draeger infinity Acute Care System Draeger standalone Infinity M540 Patient Monitor |
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors versions VG4.1.1, VG4.0.3, and lower (with VG4.2 partially affected) contain a network message handling vulnerability that allows remote attackers to inject spoofed or tampered data and cause denial-of-service conditions. Attackers can compromise network communications to modify device settings such as alarm states or alarm limits, or overwhelm the system with excessive network traffic causing the Cockpit or M540 to reboot and lose network functionality. | |
| Title | Dräger Infinity M540 VG4.1.1 Spoofed Network Message Handling DoS/Tampering | |
| Weaknesses | CWE-345 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-06-02T21:06:40.281Z
Updated: 2026-06-03T12:45:51.502Z
Reserved: 2026-06-02T21:02:24.899Z
Link: CVE-2022-4992
Updated: 2026-06-03T12:45:47.845Z
Status : Received
Published: 2026-06-02T22:16:15.660
Modified: 2026-06-02T22:16:15.660
Link: CVE-2022-4992
No data.