Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software versions VG4.1.1, VG4.0.3, and lower contain network message handling vulnerabilities that allow network-adjacent attackers to spoof or tamper with data and cause denial-of-service conditions. Attackers with access to an enabled Infinity network port or physical proximity to a wireless access point can modify device settings such as alarm states or alarm limits, and overwhelm the system with incoming data causing the device to reboot and lose network functionality.

Project Subscriptions

Vendors Products
Draeger Subscribe
Infinity Acute Care System Subscribe
Standalone Infinity M540 Patient Monitor Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 03 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
References

Wed, 03 Jun 2026 16:00:00 +0000


Wed, 03 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Draeger
Draeger infinity Acute Care System
Draeger standalone Infinity M540 Patient Monitor
Vendors & Products Draeger
Draeger infinity Acute Care System
Draeger standalone Infinity M540 Patient Monitor

Tue, 02 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 02 Jun 2026 14:15:00 +0000

Type Values Removed Values Added
Description Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software versions VG4.1.1, VG4.0.3, and lower contain network message handling vulnerabilities that allow network-adjacent attackers to spoof or tamper with data and cause denial-of-service conditions. Attackers with access to an enabled Infinity network port or physical proximity to a wireless access point can modify device settings such as alarm states or alarm limits, and overwhelm the system with incoming data causing the device to reboot and lose network functionality.
Title Dräger Infinity M540 VG4.1.1 Spoofing and DoS via Network Message Handling
Weaknesses CWE-924
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-06-03T15:43:03.688Z

Reserved: 2026-06-02T13:54:01.021Z

Link: CVE-2019-25719

cve-icon Vulnrichment

Updated: 2026-06-02T14:56:27.160Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-02T14:16:25.627

Modified: 2026-06-03T16:16:17.130

Link: CVE-2019-25719

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-02T20:51:11Z

Weaknesses