Executive brief
Dräger Infinity patient monitors, used in hospitals to track vital signs, are vulnerable to network-based attacks. An attacker with access to the hospital network or wireless access points can remotely change critical device settings like alarm limits or crash the device entirely. This could lead to missed medical emergencies or a total loss of patient monitoring capabilities during clinical operations.
Technical details
The vulnerability is classified as an improper enforcement of message integrity (CWE-924) within the network message handling component of the Dräger Infinity software. Attackers with network adjacency—either through a physical Infinity network port or proximity to a wireless access point—can send malicious traffic to the device without authentication. This allows for the unauthorized modification of device settings, such as alarm states and limits, or the injection of excessive data to trigger a system reboot. Successful exploitation results in a denial-of-service (DoS) and loss of network monitoring functionality. Affected versions include VG4.1.1, VG4.0.3, and earlier.
Affected products
- Dräger Infinity Acute Care System VG4.1.1, VG4.0.3, and lower
- Dräger Standalone Infinity M540 patient monitor VG4.1.1, VG4.0.3, and lower
Timeline
- 2026-06-02: advisory: NVD and VulnCheck published advisory details.