CVE-2022-4992
Published: Jun 2, 2026
Modified: Jun 5, 2026
CVSS v3.1
8.6
Description
Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors versions VG4.1.1, VG4.0.3, and lower (with VG4.2 partially affected) contain a network message handling vulnerability that allows remote attackers to inject spoofed or tampered data and cause denial-of-service conditions. Attackers can compromise network communications to modify device settings such as alarm states or alarm limits, or overwhelm the system with excessive network traffic causing the Cockpit or M540 to reboot and lose network functionality.
| Vendor | Product | Versions |
|---|---|---|
Dräger | Infinity Acute Care System | affected 0 - < VG4.2affected 0 - < VG4.1.1affected 0 - < VG4.0.3 |
Dräger | Standalone Infinity M540 patient monitor | affected 0 - < VG4.2affected 0 - < VG4.1.1 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now