CVE-2019-13539 details a weak password hashing vulnerability (CWE-326, CWE-328) in Medtronic Valleylab Exchange Client (v3.4 and below), Valleylab FT10 Energy Platform (v4.0.0 and below), and Valleylab FX8 Energy Platform (v1.1.0 and below). These devices utilize the outdated descrypt algorithm for OS password hashing, making stored credentials susceptible to brute-force attacks. Rated with a CVSS score of 7.8 (HIGH), this vulnerability allows an attacker with local access (AV:L, PR:L) to achieve high confidentiality, integrity, and availability impacts (C:H, I:H, A:H) by cracking the weak hashes. While direct network logons are disabled, other reported vulnerabilities could grant local shell access, enabling an attacker to obtain these hashes. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Despite its age, the vulnerability has garnered limited community discussion and media coverage, with one article from SecurityWeek highlighting DHS warnings regarding critical flaws in Medtronic medical devices.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.4CPE matchmatch criteria | cpe:2.3:a:medtronic:valleylab_exchange_client:*:*:*:*:*:*:*:* | ||
<= 4.0.0CPE matchmatch criteria | cpe:2.3:o:medtronic:valleylab_ft10_energy_platform_firmware:*:*:*:*:*:*:*:* | ||
<= 1.1.0CPE matchmatch criteria | cpe:2.3:o:medtronic:valleylab_fx8_energy_platform_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.