CVE-2022-1517
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
LRM utilizes elevated privileges. An unauthenticated malicious actor can upload and execute code remotely at the operating system level, which can allow an attacker to change settings, configurations, software, or access sensitive data on the affected produc. An attacker could also exploit this vulnerability to access APIs not intended for general use and interact through the network.
Affected (1)
Products: Illumina: Local Run Manager
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.3 to 3.1 |
| Running on/with | Platform Versions |
|---|---|
Illumina Iseq 100 | All versions |
Illumina Miniseq | All versions |
Illumina Miseq | All versions |
Illumina Miseq Dx | All versions |
Illumina Nextseq 500 | All versions |
Illumina Nextseq 550 | All versions |
Illumina Nextseq 550dx | All versions |
Related CWEs
CWE-250
Execution with Unnecessary Privileges
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
CWE-269
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
References (2)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.