CVE-2019-13535
4.6
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 0.9 / Impact: 3.6
Source: NVD
Description
In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleylab LS10 Energy Platform (VLLS10GEN—not available in the United States) version 1.20.2 and lower, the RFID security mechanism does not apply read protection, allowing for full read access of the RFID security mechanism data.
Affected (3)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0.3 |
| Running on/with | Platform Versions |
|---|---|
Medtronic Valleylab Ft10 Energy Platform | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.20.2 |
| Running on/with | Platform Versions |
|---|---|
Medtronic Valleylab Ls10 Energy Platform | All versions |
Related CWEs
CWE-693
Protection Mechanism Failure
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
CWE-732
Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
References (3)
Source: ics-cert@hq.dhs.gov
Source: ics-cert@hq.dhs.gov
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.