Medtronic Valleylab Exchange Client 3.4及之前版本、Valleylab FT10 Energy Platform (VLFT10GEN) 4.0.0及之前版本和Valleylab FX8 Energy Platform (VLFX8GEN) 1.1.0及之前版本中存在输入验证错误漏洞,该漏洞源于程序使用descrypt算法进行OS密码哈希处理。攻击者可借助特制请求利用该漏洞获取本地shell的访问权限并访问这些哈希值。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Medtronic | Valleylab Exchange Client | 0 ~ 3.4 | - |
|
| Medtronic | Valleylab FT10 Energy Platform (VLFT10GEN) | 0 ~ software version 4.0.0 | - |
|
| Medtronic | Valleylab FX8 Energy Platform (VLFX8GEN) | 0 ~ software version 1.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2019-13543 | 5.8 MEDIUM | Medtronic Valleylab FT10 and FX8 Use of Hard-coded Credentials |
| CVE-2019-13531 | 4.8 MEDIUM | Medtronic Valleylab FT10 and LS10 Improper Authentication |
| CVE-2019-13535 | 4.6 MEDIUM | Medtronic Valleylab FT10 and LS10 Protection Mechanism Failure |
No comments yet