Executive brief
Dräger Infinity M300 patient monitors, which are wireless devices used to track patient vital signs, are vulnerable to a network-based attack. An attacker on the same local network can remotely crash the device, causing it to reboot or enter a failure state. This results in a loss of patient monitoring and wireless connectivity, potentially delaying medical response until the device is manually restarted.
Technical details
A network-based denial of service vulnerability exists in Dräger Infinity M300 patient worn monitors (software version VG2.3.1 and earlier) due to uncontrolled resource consumption (CWE-400). An unauthenticated attacker located on the same Infinity Network can send malicious requests to the device to trigger a reboot or a fail state. Successful exploitation results in the loss of wireless connectivity and the interruption of patient monitoring functionality, requiring a manual restart to restore service. The vulnerability is reachable via the adjacent network without user interaction.
Affected products
- Dräger Infinity M300 patient worn monitor VG2.3.1 and earlier
Timeline
- 2026-06-02: advisory: Advisory published by VulnCheck and NVD