Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6jx8-hc3v-28hr

Опубликовано: 03 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.8
CVSS3: 8.6

Описание

Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors versions VG4.1.1, VG4.0.3, and lower (with VG4.2 partially affected) contain a network message handling vulnerability that allows remote attackers to inject spoofed or tampered data and cause denial-of-service conditions. Attackers can compromise network communications to modify device settings such as alarm states or alarm limits, or overwhelm the system with excessive network traffic causing the Cockpit or M540 to reboot and lose network functionality.

Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors versions VG4.1.1, VG4.0.3, and lower (with VG4.2 partially affected) contain a network message handling vulnerability that allows remote attackers to inject spoofed or tampered data and cause denial-of-service conditions. Attackers can compromise network communications to modify device settings such as alarm states or alarm limits, or overwhelm the system with excessive network traffic causing the Cockpit or M540 to reboot and lose network functionality.

EPSS

Процентиль: 6%
0.0016
Низкий

8.8 High

CVSS4

8.6 High

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 8.6
nvd
2 месяца назад

Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors versions VG4.1.1, VG4.0.3, and lower (with VG4.2 partially affected) contain a network message handling vulnerability that allows remote attackers to inject spoofed or tampered data and cause denial-of-service conditions. Attackers can compromise network communications to modify device settings such as alarm states or alarm limits, or overwhelm the system with excessive network traffic causing the Cockpit or M540 to reboot and lose network functionality.

EPSS

Процентиль: 6%
0.0016
Низкий

8.8 High

CVSS4

8.6 High

CVSS3

Дефекты

CWE-345