CVE-2019-25719
Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software versions VG4.1.1, VG4.0.3, and lower contain network message handling vulnerabilities that allow network-adjacent attackers to spoof or tamper with data and cause denial-of-service conditions. Attackers with access to an enabled Infinity network port or physical proximity to a wireless access point can modify device settings such as alarm states or alarm limits, and overwhelm the system with incoming data causing the device to reboot and lose network functionality.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.13%
- CWE
- CWE-924
- Published
- 2026-06-02
- Last modified
- 2026-06-03
Affected products
- Dräger Infinity Acute Care System
- Dräger Infinity Acute Care System
- Dräger Infinity Acute Care System
- Dräger Infinity Acute Care System
- Dräger Standalone Infinity M540 patient monitor
- Dräger Standalone Infinity M540 patient monitor
- Dräger Standalone Infinity M540 patient monitor
- Dräger Infinity Acute Care System
Weakness type
Related vulnerabilities
- CVE-2026-48106 — Arc Enterprise cluster replication accepts unauthenticated MsgReplicateSync messages, enabling cluster-wide data injection from any TLS-trusted peer
- CVE-2026-68554 — Coturn: STUN attributes after MESSAGE-INTEGRITY are processed, letting on-path attackers modify authenticated TURN requests
- CVE-2026-14681 — PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL
- CVE-2026-13584 — Information tampering and Denial-of-service (DoS) vulnerability in CC-Link IE TSN communication protocol
- CVE-2026-54891 — Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl
- CVE-2026-12576 — DVP80ES3 Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability
- CVE-2025-29628 — An issue in Gardyn 4 allows a remote attacker to obtain sensitive information and execute arbitrary...
- CVE-2025-0592 — SICK Lector8xx and InspectorP8xx vulnerable for code execution