Description
Instruments with Illumina Universal Copy Service v1.x and
v2.x contain an unnecessary privileges vulnerability. An unauthenticated
malicious actor could upload and execute code remotely at the operating system
level, which could allow an attacker to change settings, configurations,
software, or access sensitive data on the affected product.





Published: 2023-04-28
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Workaround

Illumina recommends using the UCS Vulnerability Instructions Guide https://support.illumina.com/downloads/illumina-universal-copy-service-1-0.html  based on the user’s specific system configuration to mitigate the vulnerabilities. Illumina recommends users read the instructions before downloading any software.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-24152 Instruments with Illumina Universal Copy Service v1.x and v2.x contain an unnecessary privileges vulnerability. An unauthenticated malicious actor could upload and execute code remotely at the operating system level, which could allow an attacker to change settings, configurations, software, or access sensitive data on the affected product.
History

Thu, 16 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Illumina Iscan Iscan Firmware Iseq 100 Iseq 100 Firmware Miniseq Miniseq Firmware Miseq Miseq Firmware Miseqdx Miseqdx Firmware Nextseq 1000 Nextseq 1000 Firmware Nextseq 2000 Nextseq 2000 Firmware Nextseq 500 Nextseq 500 Firmware Nextseq 550 Nextseq 550 Firmware Nextseq 550dx Nextseq 550dx Firmware Novaseq 6000 Novaseq 6000 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-01-16T21:35:30.057Z

Reserved: 2023-04-10T14:50:41.262Z

Link: CVE-2023-1966

cve-icon Vulnrichment

Updated: 2024-08-02T06:05:27.096Z

cve-icon NVD

Status : Modified

Published: 2023-04-28T19:15:16.573

Modified: 2024-11-21T07:40:14.730

Link: CVE-2023-1966

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses