CVE-2019-13531
Published: Nov 8, 2019
Modified: May 22, 2025
CVSS v3.1
4.8
Description
In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleylab LS10 Energy Platform (VLLS10GEN—not available in the United States) version 1.20.2 and lower, the RFID security mechanism used for authentication between the FT10/LS10 Energy Platform and instruments can be bypassed, allowing for inauthentic instruments to connect to the generator.
| Vendor | Product | Versions |
|---|---|---|
Medtronic | Valleylab FT10 Energy Platform (VLFT10GEN) | affected 0 - <= 2.1.0affected 0 - <= 2.0.3 |
Medtronic | Valleylab LS10 Energy Platform (VLLS10GEN—not available in the United States) | affected 0 - <= 1.20.2 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now