Network Message Handling Vulnerability in Dräger Patient Monitors
CVE-2022-4992

8.8HIGH

What is CVE-2022-4992?

The Infinity Acute Care System and Standalone Infinity M540 patient monitors by Dräger exhibit a vulnerability in their network message handling. This flaw allows remote attackers to inject spoofed or tampered messages, potentially leading to denial-of-service attacks. By manipulating network communications, assailants can alter crucial device settings, such as alarm states and limits. Moreover, they can overwhelm the system with increased network traffic, causing devices to reboot and impairing their network capabilities. This vulnerability can significantly jeopardize patient safety and operational efficiency.

Affected Version(s)

Infinity Acute Care System 0

Infinity Acute Care System 0

Infinity Acute Care System 0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.