Bypass of RFID Authentication in Medtronic Valleylab FT10 and LS10 Energy Platforms
CVE-2019-13531

4.6MEDIUM

What is CVE-2019-13531?

The Medtronic Valleylab FT10 and LS10 Energy Platforms have a vulnerability allowing unauthorized instruments to connect to the energy generator. This is due to a bypass in the RFID security mechanism used for authentication, compromising the integrity of connected instruments. The vulnerability affects specific versions of the FT10 and LS10 platforms, posing potential risks in clinical settings. It's crucial for users to ensure that their devices are updated to mitigate any security concerns.

Affected Version(s)

Valleylab FT10 Energy Platform (VLFT10GEN) 0 <= 2.1.0

Valleylab FT10 Energy Platform (VLFT10GEN) 0 <= 2.0.3

Valleylab LS10 Energy Platform (VLLS10GEN—not available in the United States) 0 <= 1.20.2

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.