CVE-2023-1966
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Instruments with Illumina Universal Copy Service v1.x and
v2.x contain an unnecessary privileges vulnerability. An unauthenticated
malicious actor could upload and execute code remotely at the operating system
level, which could allow an attacker to change settings, configurations,
software, or access sensitive data on the affected product.
Affected (16)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0.0 |
| Running on/with | Platform Versions |
|---|---|
Illumina Iscan | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Illumina Iseq 100 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.0 |
| Running on/with | Platform Versions |
|---|---|
Illumina Miniseq | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.0 |
| Running on/with | Platform Versions |
|---|---|
Illumina Miseq | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.0.1 |
| Running on/with | Platform Versions |
|---|---|
Illumina Miseqdx | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0 |
| Running on/with | Platform Versions |
|---|---|
Illumina Nextseq 500 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0 |
| Running on/with | Platform Versions |
|---|---|
Illumina Nextseq 550 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0.0 to 1.3.1 |
| Running on/with | Platform Versions |
|---|---|
Illumina Nextseq 550dx | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.1 |
| Running on/with | Platform Versions |
|---|---|
Illumina Nextseq 1000 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.1 |
| Running on/with | Platform Versions |
|---|---|
Illumina Nextseq 2000 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.7 |
| Running on/with | Platform Versions |
|---|---|
Illumina Novaseq 6000 | All versions |
Related CWEs
CWE-250
Execution with Unnecessary Privileges
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
CWE-269
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
References (4)
Source: ics-cert@hq.dhs.gov
Vendor Advisory
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.