Reversible One-Way Hash in Medtronic products - CVE-2019-13539
Published: November 11, 2019
Vulnerability identifier: #VU22639
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13539
CWE-ID:
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to bypass authentication on the target system.
The vulnerability exists due to the the affected products use the decrypt algorithm for OS password hashing. While interactive, network-based logins are disable and local user can use other vulnerabilities to obtain local shell access and access these hashes.
Affected software
Valleylab FX8 Energy Platform
Valleylab FT10 Energy Platform
Valleylab Exchange Client
Amazon Linux AMI
Gentoo Linux
Opensuse
Valleylab FT10 Energy Platform
Valleylab Exchange Client
Amazon Linux AMI
Gentoo Linux
Opensuse
How to mitigate CVE-2019-13539
Install updates from vendor's website.