Junglewise Threat Intelligence

CVE-2022-4992: Dräger Infinity Patient Monitors Insufficient Data Verification

CVE-2022-4992 · Severity: high · CVSS 8.6 · Published 2026-06-02

Vendors: Dräger.

Executive brief

Dräger patient monitoring systems used in hospitals contain a flaw in how they process network messages. An attacker could remotely interfere with these devices to change critical settings like alarm limits or force the monitors to reboot. This could lead to a loss of patient monitoring capabilities or the failure of medical staff to be alerted to life-threatening patient conditions.

Technical details

The vulnerability is classified as CWE-345 (Insufficient Verification of Data Authenticity) within the network message handling component of the Dräger Infinity systems. A remote, unauthenticated attacker can send specially crafted network traffic to the device to inject spoofed or tampered data. This can be used to modify device configurations, such as alarm states and limits, or to launch a denial-of-service attack by overwhelming the system with traffic. Successful exploitation can cause the M540 monitor or the Cockpit interface to reboot, resulting in a total loss of network functionality and monitoring during the restart period.

Affected products

  • Dräger Infinity Acute Care System VG4.1.1, VG4.0.3, and lower; VG4.2 partially affected
  • Dräger Standalone Infinity M540 patient monitor VG4.1.1, VG4.0.3, and lower; VG4.2 partially affected

Timeline

  • 2026-06-02: disclosed
  • 2026-06-02: advisory

References

Related threats