Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software versions VG4.1.1, VG4.0.3, and lower contain network message handling vulnerabilities that allow network-adjacent attackers to spoof or tamper with data and cause denial-of-service conditions. Attackers with access to an enabled Infinity network port or physical proximity to a wireless access point can modify device settings such as alarm states or alarm limits, and overwhelm the system with incoming data causing the device to reboot and lose network functionality.
Metrics
Affected Vendors & Products
References
History
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Draeger
Draeger infinity Acute Care System Draeger standalone Infinity M540 Patient Monitor |
|
| Vendors & Products |
Draeger
Draeger infinity Acute Care System Draeger standalone Infinity M540 Patient Monitor |
Tue, 02 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Jun 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software versions VG4.1.1, VG4.0.3, and lower contain network message handling vulnerabilities that allow network-adjacent attackers to spoof or tamper with data and cause denial-of-service conditions. Attackers with access to an enabled Infinity network port or physical proximity to a wireless access point can modify device settings such as alarm states or alarm limits, and overwhelm the system with incoming data causing the device to reboot and lose network functionality. | |
| Title | Dräger Infinity M540 VG4.1.1 Spoofing and DoS via Network Message Handling | |
| Weaknesses | CWE-924 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-06-02T14:00:52.578Z
Updated: 2026-06-02T14:56:35.870Z
Reserved: 2026-06-02T13:54:01.021Z
Link: CVE-2019-25719
Updated: 2026-06-02T14:56:27.160Z
Status : Awaiting Analysis
Published: 2026-06-02T14:16:25.627
Modified: 2026-06-02T14:40:32.283
Link: CVE-2019-25719
No data.
ReportizFlow