← Back

CVE-2019-13539

nvd nist
Published: Nov 8, 2019Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use the descrypt algorithm for OS password hashing. While interactive, network-based logons are disabled, and attackers can use the other vulnerabilities within this report to obtain local shell access and access these hashes.

Affected (3)

3 products
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 3.4
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 4.0.0
Running on/withPlatform Versions
Medtronic
Valleylab Ft10 Energy Platform
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.1.0
Running on/withPlatform Versions
Medtronic
Valleylab Fx8 Energy Platform
All versions

Timeline

No history available yet.