CVE-2022-4992 - CVE House
Back to Database
Status published High CVE-2022-4992

Dräger Infinity M540 VG4.1.1 Spoofed Network Message Handling DoS/Tampering

Vulnerability Description

Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors versions VG4.1.1, VG4.0.3, and lower (with VG4.2 partially affected) contain a network message handling vulnerability that allows remote attackers to inject spoofed or tampered data and cause denial-of-service conditions. Attackers can compromise network communications to modify device settings such as alarm states or alarm limits, or overwhelm the system with excessive network traffic causing the Cockpit or M540 to reboot and lose network functionality.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-4992

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Infinity Acute Care System, Standalone Infinity M540 patient monitor
Vulnerable Versions:
0

Timeline

Official Publish: June 2nd, 2026
Last Modified: June 5th, 2026
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Weaknesses (CWE)