v2.x contain an unnecessary privileges vulnerability. An unauthenticated
malicious actor could upload and execute code remotely at the operating system
level, which could allow an attacker to change settings, configurations,
software, or access sensitive data on the affected product.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Illumina
Subscribe
|
Iscan
Subscribe
Iscan Firmware
Subscribe
Iseq 100
Subscribe
Iseq 100 Firmware
Subscribe
Miniseq
Subscribe
Miniseq Firmware
Subscribe
Miseq
Subscribe
Miseq Firmware
Subscribe
Miseqdx
Subscribe
Miseqdx Firmware
Subscribe
Nextseq 1000
Subscribe
Nextseq 1000 Firmware
Subscribe
Nextseq 2000
Subscribe
Nextseq 2000 Firmware
Subscribe
Nextseq 500
Subscribe
Nextseq 500 Firmware
Subscribe
Nextseq 550
Subscribe
Nextseq 550 Firmware
Subscribe
Nextseq 550dx
Subscribe
Nextseq 550dx Firmware
Subscribe
Novaseq 6000
Subscribe
Novaseq 6000 Firmware
Subscribe
|
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-24152 | Instruments with Illumina Universal Copy Service v1.x and v2.x contain an unnecessary privileges vulnerability. An unauthenticated malicious actor could upload and execute code remotely at the operating system level, which could allow an attacker to change settings, configurations, software, or access sensitive data on the affected product. |
Solution
No solution given by the vendor.
Workaround
Illumina recommends using the UCS Vulnerability Instructions Guide https://support.illumina.com/downloads/illumina-universal-copy-service-1-0.html based on the user’s specific system configuration to mitigate the vulnerabilities. Illumina recommends users read the instructions before downloading any software.
Thu, 16 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-01-16T21:35:30.057Z
Reserved: 2023-04-10T14:50:41.262Z
Link: CVE-2023-1966
Updated: 2024-08-02T06:05:27.096Z
Status : Modified
Published: 2023-04-28T19:15:16.573
Modified: 2024-11-21T07:40:14.730
Link: CVE-2023-1966
No data.
OpenCVE Enrichment
No data.
EUVD