CVE-2022-4992
Dräger Infinity M540 VG4.1.1 Spoofed Network Message Handling DoS/Tampering
CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
14th
Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors versions VG4.1.1, VG4.0.3, and lower (with VG4.2 partially affected) contain a network message handling vulnerability that allows remote attackers to inject spoofed or tampered data and cause denial-of-service conditions. Attackers can compromise network communications to modify device settings such as alarm states or alarm limits, or overwhelm the system with excessive network traffic causing the Cockpit or M540 to reboot and lose network functionality.
| CWE | CWE-345 |
| Vendor | dräger |
| Product | infinity acute care system |
| Published | Jun 2, 2026 |
| Last Updated | Jun 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for dräger infinity acute care system
Be the first to know when new high vulnerabilities affecting dräger infinity acute care system are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
High
Affected Versions
Dräger / Infinity Acute Care System
0 < VG4.2 0 < VG4.1.1 0 < VG4.0.3
Dräger / Standalone Infinity M540 patient monitor
0 < VG4.2 0 < VG4.1.1