Junglewise Threat Intelligence

CVE-2019-25721: Dräger Infinity M300 denial of service in patient worn monitors

CVE-2019-25721 · Severity: medium · CVSS 6.5 · Published 2026-06-02

Vendors: Dräger.

Executive brief

Dräger Infinity M300 patient monitors, which are wireless devices used to track patient vital signs, are vulnerable to a network-based attack. An attacker on the same local network can remotely crash the device, causing it to reboot or enter a failure state. This results in a loss of patient monitoring and wireless connectivity, potentially delaying medical response until the device is manually restarted.

Technical details

A network-based denial of service vulnerability exists in Dräger Infinity M300 patient worn monitors (software version VG2.3.1 and earlier) due to uncontrolled resource consumption (CWE-400). An unauthenticated attacker located on the same Infinity Network can send malicious requests to the device to trigger a reboot or a fail state. Successful exploitation results in the loss of wireless connectivity and the interruption of patient monitoring functionality, requiring a manual restart to restore service. The vulnerability is reachable via the adjacent network without user interaction.

Affected products

  • Dräger Infinity M300 patient worn monitor VG2.3.1 and earlier

Timeline

  • 2026-06-02: advisory: Advisory published by VulnCheck and NVD

References

Related threats