CVE-2019-13543

MEDIUM

Medtronic Valleylab - Info Disclosure

Title source: llm
STIX 2.1

Description

Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use multiple sets of hard-coded credentials. If discovered, they can be used to read files on the device.

Scores

CVSS v3 5.8
EPSS 0.0190
EPSS Percentile 76.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Details

CWE
CWE-798
Status published
Products (3)
medtronic/valleylab_exchange_client < 3.4
medtronic/valleylab_ft10_energy_platform_firmware < 4.0.0
medtronic/valleylab_fx8_energy_platform_firmware < 1.1.0
Published Nov 08, 2019
Tracked Since Feb 18, 2026