Reversible One-Way Hash in Medtronic products - CVE-2019-13539

 

Reversible One-Way Hash in Medtronic products - CVE-2019-13539

Published: November 11, 2019


Vulnerability identifier: #VU22639
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13539
CWE-ID:
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass authentication on the target system.

The vulnerability exists due to the the affected products use the decrypt algorithm for OS password hashing. While interactive, network-based logins are disable and local user can use other vulnerabilities to obtain local shell access and access these hashes.

Affected software

Valleylab FX8 Energy Platform
Valleylab FT10 Energy Platform
Valleylab Exchange Client
Amazon Linux AMI
Gentoo Linux
Opensuse

How to mitigate CVE-2019-13539

Install updates from vendor's website.


External References

Related Security Bulletins