CVE-2022-4992 PUBLISHED

Dräger Infinity M540 VG4.1.1 Spoofed Network Message Handling DoS/Tampering

Assigner: VulnCheck
Reserved: 02.06.2026 Published: 02.06.2026 Updated: 03.06.2026

Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors versions VG4.1.1, VG4.0.3, and lower (with VG4.2 partially affected) contain a network message handling vulnerability that allows remote attackers to inject spoofed or tampered data and cause denial-of-service conditions. Attackers can compromise network communications to modify device settings such as alarm states or alarm limits, or overwhelm the system with excessive network traffic causing the Cockpit or M540 to reboot and lose network functionality.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.8

Product Status

Vendor Dräger
Product Infinity Acute Care System
Versions Default: unknown
  • affected from 0 to VG4.2 (excl.)
  • affected from 0 to VG4.1.1 (excl.)
  • affected from 0 to VG4.0.3 (excl.)
Vendor Dräger
Product Standalone Infinity M540 patient monitor
Versions Default: unknown
  • affected from 0 to VG4.2 (excl.)
  • affected from 0 to VG4.1.1 (excl.)

References

Problem Types

  • CWE-345 Insufficient Verification of Data Authenticity CWE