CVE-2023-1968
CRITICAL
10.0
CVSS 3.1
Description
Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An unauthenticated malicious actor could use UCS to listen on all IP addresses, including those capable of accepting remote communications.
Metadata
Severity & Metrics
10.0
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (11)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Illumina | iScan Control Software | — | 4.0.0, 4.0.5 |
| Illumina | iSeq 100 | — | All versions |
| Illumina | MiniSeq Control Software | — | 2.0 |
| Illumina | MiSeq Control Software | — | 4.0 (RUO Mode) |
| Illumina | MiSeqDx Operating Software | — | 4.0.1 |
| Illumina | NextSeq 1000/2000 Control Software | — | 0 ≤ 1.4.1 |
| Illumina | NextSeq 500/550 Control Software | — | 4.0 |
| Illumina | NextSeq 550Dx Control Software | — | 4.0 (RUO Mode) |
| Illumina | NextSeq 550Dx Operating Software | — | 1.0.0 ≤ 1.3.1, 1.3.3 |
| Illumina | NovaSeq 6000 Control Software | — | 0 ≤ 1.7 |
| Illumina | NovaSeq Control Software | — | 1.8 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-1327 | cna | CWE-1327 Binding to an Unrestricted IP Address |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 10.0 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
References (2)