Back to overview

CVE-2023-1968

CRITICAL
10.0
CVSS 3.1
Description
Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An unauthenticated malicious actor could use UCS to listen on all IP addresses, including those capable of accepting remote communications.

Metadata

CVE ID
CVE-2023-1968
State
PUBLISHED
Assigner
icscert
Reserved
2023-04-10 14:51 UTC
Published
2023-04-28 18:09 UTC
Last updated
2025-01-16 21:35 UTC
Primary CWE
CWE-1327
CWE-1327 Binding to an Unrestricted IP Address
Vendor / Product
Illumina / iScan Control Software
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (11)
VendorProductPlatformVersions
Illumina iScan Control Software 4.0.0, 4.0.5
Illumina iSeq 100 All versions
Illumina MiniSeq Control Software 2.0
Illumina MiSeq Control Software 4.0 (RUO Mode)
Illumina MiSeqDx Operating Software 4.0.1
Illumina NextSeq 1000/2000 Control Software 0 ≤ 1.4.1
Illumina NextSeq 500/550 Control Software 4.0
Illumina NextSeq 550Dx Control Software 4.0 (RUO Mode)
Illumina NextSeq 550Dx Operating Software 1.0.0 ≤ 1.3.1, 1.3.3
Illumina NovaSeq 6000 Control Software 0 ≤ 1.7
Illumina NovaSeq Control Software 1.8
Weakness (CWE)
CWESourceDescription
CWE-1327 cna CWE-1327 Binding to an Unrestricted IP Address
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview