Network Message Handling Vulnerabilities in Dräger Infinity Acute Care System and M540 Monitors
CVE-2019-25719

8.8HIGH

What is CVE-2019-25719?

The Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors exhibit vulnerabilities in network message handling. These flaws allow network-adjacent attackers to spoof or alter data, leading to potential denial-of-service conditions. An attacker with access to an enabled network port or who is in close proximity to a wireless access point can disturb device settings, including alarm states and limits. This manipulation can flood the system with data, triggering a reboot and resulting in a loss of network connectivity, which poses significant risks in critical healthcare environments.

Affected Version(s)

Infinity Acute Care System VG4.1.1

Infinity Acute Care System VG4.0.3

Infinity Acute Care System lower than VG4.0.3

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.