CVE-2019-25719 PUBLISHED

Dräger Infinity M540 VG4.1.1 Spoofing and DoS via Network Message Handling

Assigner: VulnCheck
Reserved: 02.06.2026 Published: 02.06.2026 Updated: 02.06.2026

Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software versions VG4.1.1, VG4.0.3, and lower contain network message handling vulnerabilities that allow network-adjacent attackers to spoof or tamper with data and cause denial-of-service conditions. Attackers with access to an enabled Infinity network port or physical proximity to a wireless access point can modify device settings such as alarm states or alarm limits, and overwhelm the system with incoming data causing the device to reboot and lose network functionality.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.8

Product Status

Vendor Dräger
Product Infinity Acute Care System
Versions Default: unknown
  • Version VG4.1.1 is affected
  • Version VG4.0.3 is affected
  • Version lower than VG4.0.3 is affected
  • Version VG4.2 is unaffected
Vendor Dräger
Product Standalone Infinity M540 patient monitor
Versions Default: unknown
  • Version VG4.1.1 is affected
  • Version lower than VG4.1.1 is affected
  • Version VG4.2 is unaffected

References

Problem Types

  • CWE-924 Improper Enforcement of Message Integrity During Transmission in a Communication Channel CWE