Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-13539

Опубликовано: 08 нояб. 2019
Источник: nvd
CVSS3: 7
CVSS3: 7.8
CVSS2: 7.2
EPSS Низкий

Описание

Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use the descrypt algorithm for OS password hashing. While interactive, network-based logons are disabled, and attackers can use the other vulnerabilities within this report to obtain local shell access and access these hashes.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:medtronic:valleylab_exchange_client:*:*:*:*:*:*:*:*
Версия до 3.4 (включая)
Конфигурация 2

Одновременно

cpe:2.3:o:medtronic:valleylab_ft10_energy_platform_firmware:*:*:*:*:*:*:*:*
Версия до 4.0.0 (включая)
cpe:2.3:h:medtronic:valleylab_ft10_energy_platform:-:*:*:*:*:*:*:*
Конфигурация 3

Одновременно

cpe:2.3:o:medtronic:valleylab_fx8_energy_platform_firmware:*:*:*:*:*:*:*:*
Версия до 1.1.0 (включая)
cpe:2.3:h:medtronic:valleylab_fx8_energy_platform:-:*:*:*:*:*:*:*

EPSS

Процентиль: 44%
0.00213
Низкий

7 High

CVSS3

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-328
CWE-326

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use the descrypt algorithm for OS password hashing. While interactive, network-based logons are disabled, and attackers can use the other vulnerabilities within this report to obtain local shell access and access these hashes.

EPSS

Процентиль: 44%
0.00213
Низкий

7 High

CVSS3

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-328
CWE-326