PT-2026-45862 · Dräger · Infinity Acute Care System+1
CVE-2022-4992
·
Published
2026-06-02
·
Updated
2026-06-03
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors versions prior to VG4.2
Description
A network message handling issue allows remote attackers to inject spoofed or tampered data. This can lead to denial-of-service conditions by overwhelming the system with excessive network traffic, causing the Cockpit or M540 to reboot and lose network functionality. Additionally, attackers can compromise network communications to modify device settings, including alarm states or alarm limits.
Recommendations
Update to version VG4.2 or later.
Fix
DoS
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Infinity Acute Care System
Infinity M540