CVE-2019-25719

Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software versions VG4.1.1, VG4.0.3, and lower contain network message handling vulnerabilities that allow network-adjacent attackers to spoof or tamper with data and cause denial-of-service conditions. Attackers with access to an enabled Infinity network port or physical proximity to a wireless access point can modify device settings such as alarm states or alarm limits, and overwhelm the system with incoming data causing the device to reboot and lose network functionality.
Configurations

No configuration.

History

22 Jul 2026, 19:10

Type Values Removed Values Added
Summary
  • (es) Los monitores de paciente Dräger Infinity Acute Care System y Standalone Infinity M540 que ejecutan versiones de software VG4.1.1, VG4.0.3 y anteriores contienen vulnerabilidades en el manejo de mensajes de red que permiten a atacantes adyacentes a la red suplantar o manipular datos y causar condiciones de denegación de servicio. Los atacantes con acceso a un puerto de red Infinity habilitado o proximidad física a un punto de acceso inalámbrico pueden modificar la configuración del dispositivo, como los estados de alarma o los límites de alarma, y sobrecargar el sistema con datos entrantes, lo que provoca que el dispositivo se reinicie y pierda la funcionalidad de red.

03 Jun 2026, 16:16

Type Values Removed Values Added
References
  • {'url': 'https://static.draeger.com/security', 'source': 'disclosure@vulncheck.com'}
  • () https://static.draeger.com/security/download/PSA-19-255-02_Product-Security-Advisory-IACS-VG4.1.pdf -

02 Jun 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-02 14:16

Updated : 2026-07-22 19:10


NVD link : CVE-2019-25719

Mitre link : CVE-2019-25719

CVE.ORG link : CVE-2019-25719


JSON object : View

Products Affected

No product.

CWE
CWE-924

Improper Enforcement of Message Integrity During Transmission in a Communication Channel