Hard-coded Credentials Vulnerability in Medtronic Valleylab Energy Platforms
CVE-2019-13543

7.5HIGH

What is CVE-2019-13543?

The Medtronic Valleylab Exchange Client and associated energy platforms contain hard-coded credentials that can be exploited by malicious actors. This vulnerability allows unauthorized access to sensitive files stored on the device. Versions 3.4 and below for the Exchange Client as well as software versions 4.0.0 and 1.1.0 for the FT10 and FX8 platforms respectively are particularly at risk. Prompt updates to patched versions are essential to mitigate this security issue and ensure the protection of device integrity.

Affected Version(s)

Valleylab Exchange Client 0 <= 3.4

Valleylab FT10 Energy Platform (VLFT10GEN) 0

Valleylab FX8 Energy Platform (VLFX8GEN) 0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.