CVE-2019-13543
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use multiple sets of hard-coded credentials. If discovered, they can be used to read files on the device.
Affected (3)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.4 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.0.0 |
| Running on/with | Platform Versions |
|---|---|
Medtronic Valleylab Ft10 Energy Platform | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.1.0 |
| Running on/with | Platform Versions |
|---|---|
Medtronic Valleylab Fx8 Energy Platform | All versions |
References (3)
Source: ics-cert@hq.dhs.gov
Source: ics-cert@hq.dhs.gov
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.