• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-13539
Medtronic, Valleylab Fx8 Energy Platform Firmware
Minimed_508_firmware, Minimed_508, Minimed_paradigm_511_firmware, Minimed_paradigm_511, Minimed_paradigm_512_firmware, Minimed_paradigm_512, Minimed_paradigm_712_firmware, Minimed_paradigm_712, Minimed_paradigm_712e_firmware, Minimed_paradigm_712e
2020-10-09
N/A
7.8 HIGH
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use the descrypt algorithm for OS password hashing. While interactive, network-based logons are disabled, and attackers can use the other vulnerabilities within this report to obtain local shell access and access these hashes.
CVE-2019-13538
2021-06-09
N/A
8.6 HIGH
3S-Smart Software Solutions GmbH CODESYS V3 Library Manager, all versions prior to 3.5.16.0, allows the system to display active library content without checking its validity, which may allow the contents of manipulated libraries to be displayed or executed. The issue also exists for source libraries, but 3S-Smart Software Solutions GmbH strongly recommends distributing compiled libraries only.
CVE-2019-13537
Aveva, Iec870ip, Iec870ip Firmware
Iec870ip_firmware, Iec870ip
2020-02-10
N/A
7.5 HIGH
The IEC870IP driver for AVEVA’s Vijeo Citect and Citect SCADA and Schneider Electric’s Power SCADA Operation has a buffer overflow vulnerability that could result in a server-side crash.
CVE-2019-13536
2021-10-28
N/A
7.8 HIGH
Delta Electronics TPEditor, Versions 1.94 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to remotely execute arbitrary code.
CVE-2019-13535
Medtronic, Valleylab Ft10 Energy Platform Firmware
Minimed_508_firmware, Minimed_508, Minimed_paradigm_511_firmware, Minimed_paradigm_511, Minimed_paradigm_512_firmware, Minimed_paradigm_512, Minimed_paradigm_712_firmware, Minimed_paradigm_712, Minimed_paradigm_712e_firmware, Minimed_paradigm_712e
2020-10-09
N/A
4.6 MEDIUM
In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleylab LS10 Energy Platform (VLLS10GEN—not available in the United States) version 1.20.2 and lower, the RFID security mechanism does not apply read protection, allowing for full read access of the RFID security mechanism data.
CVE-2019-13534
M8105as, Philips
Hdi_4000_firmware, Hdi_4000, Intellivue_mp_monitors_mp20-mp90_firmware, M80010a, M8001a, M8002a, M8003a, M8004a, M8005a, M8007a
2019-10-09
N/A
7.2 HIGH
Philips IntelliVue WLAN, portable patient monitors, WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, Part #: M8096-67501, WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C) and WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C). The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
CVE-2019-13533
2020-01-02
N/A
8.1 HIGH
In Omron PLC CJ series, all versions, and Omron PLC CS series, all versions, an attacker could monitor traffic between the PLC and the controller and replay requests that could result in the opening and closing of industrial valves.
CVE-2019-13532
2019-10-09
N/A
7.5 HIGH
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller.
CVE-2019-13531
Medtronic, Valleylab Ft10 Energy Platform Firmware
Minimed_508_firmware, Minimed_508, Minimed_paradigm_511_firmware, Minimed_paradigm_511, Minimed_paradigm_512_firmware, Minimed_paradigm_512, Minimed_paradigm_712_firmware, Minimed_paradigm_712, Minimed_paradigm_712e_firmware, Minimed_paradigm_712e
2020-10-09
N/A
4.6 MEDIUM
In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleylab LS10 Energy Platform (VLLS10GEN—not available in the United States) version 1.20.2 and lower, the RFID security mechanism used for authentication between the FT10/LS10 Energy Platform and instruments can be bypassed, allowing for inauthentic instruments to connect to the generator.
CVE-2019-13530
M8105as, Philips
Hdi_4000_firmware, Hdi_4000, Intellivue_mp_monitors_mp20-mp90_firmware, M80010a, M8001a, M8002a, M8003a, M8004a, M8005a, M8007a
2019-10-09
N/A
7.2 HIGH
Philips IntelliVue WLAN, portable patient monitors, WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, Part #: M8096-67501, WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C) and WLAN Version B, Firmware A.01.09, Part #: N/A (Replaced by Version C). An attacker can use these credentials to login via ftp and upload a malicious firmware.
« Previous 1 … 6,281 6,282 6,283 6,284 6,285 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE