Improper Authentication in Valleylab LS10 Energy Platform and Valleylab FT10 Energy Platform - CVE-2019-13531
Published: November 11, 2019
Vulnerability details
The vulnerability allows a local attacker to bypass authentication process.
The vulnerability exists due to an error in the RFID security mechanism used for authentication between the FT10/LS10 Energy Platform and instruments. An attacker with physical access to the device can connect inauthentic instruments to the generator, bypass authentication process and gain unauthorized access to the application.
Affected software
Valleylab FT10 Energy Platform
Amazon Linux AMI
Gentoo Linux
Opensuse