Junglewise Threat Intelligence

CVE-2019-25724: Dräger Infinity M300 denial of service via network-based reboots

CVE-2019-25724 · Severity: medium · CVSS 6.5 · Published 2026-06-02

Vendors: Dräger.

Executive brief

Dräger Infinity M300 patient monitors, which are wearable devices used to track patient vital signs in hospitals, are vulnerable to a network-based attack. An attacker on the hospital network can remotely force these devices to reboot repeatedly until they stop functioning entirely. This results in a loss of patient monitoring and medical alarms, requiring staff to manually intervene and restart each affected device.

Technical details

A denial of service vulnerability exists in Dräger Infinity M300 patient monitors (versions VG2.x and earlier) due to uncontrolled resource consumption (CWE-400). An attacker with access to the hospital or Infinity Network can send malicious network traffic to trigger a device reboot. By repeatedly exploiting this, the attacker can force the device into a fail state that requires a manual hardware restart. This results in the loss of wireless connectivity, patient monitoring data, and alarm functionality. The attack requires adjacent network access but no authentication or user interaction.

Affected products

  • Dräger Infinity M300 VG2.x and earlier

Timeline

  • 2026-06-02: advisory: Advisory published by VulnCheck and NVD

References

Related threats