CVE-2023-1968
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An unauthenticated malicious actor could use UCS to listen on all IP addresses, including those capable of accepting remote communications.
Affected (16)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0.0 |
| Running on/with | Platform Versions |
|---|---|
Illumina Iscan | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Illumina Iseq 100 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.0 |
| Running on/with | Platform Versions |
|---|---|
Illumina Miniseq | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.0 |
| Running on/with | Platform Versions |
|---|---|
Illumina Miseq | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.0.1 |
| Running on/with | Platform Versions |
|---|---|
Illumina Miseqdx | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0 |
| Running on/with | Platform Versions |
|---|---|
Illumina Nextseq 500 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0 |
| Running on/with | Platform Versions |
|---|---|
Illumina Nextseq 550 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0.0 to 1.3.1 |
| Running on/with | Platform Versions |
|---|---|
Illumina Nextseq 550dx | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.1 |
| Running on/with | Platform Versions |
|---|---|
Illumina Nextseq 1000 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.1 |
| Running on/with | Platform Versions |
|---|---|
Illumina Nextseq 2000 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.7 |
| Running on/with | Platform Versions |
|---|---|
Illumina Novaseq 6000 | All versions |
References (4)
Source: ics-cert@hq.dhs.gov
Vendor Advisory
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.