PT-2026-45862 · Dräger · Infinity Acute Care System+1

CVE-2022-4992

·

Published

2026-06-02

·

Updated

2026-06-03

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors versions prior to VG4.2
Description A network message handling issue allows remote attackers to inject spoofed or tampered data. This can lead to denial-of-service conditions by overwhelming the system with excessive network traffic, causing the Cockpit or M540 to reboot and lose network functionality. Additionally, attackers can compromise network communications to modify device settings, including alarm states or alarm limits.
Recommendations Update to version VG4.2 or later.

Fix

DoS

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-4992

Affected Products

Infinity Acute Care System
Infinity M540