Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An unauthenticated malicious actor could use UCS to listen on all IP addresses, including those capable of accepting remote communications.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-24154 | Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An unauthenticated malicious actor could use UCS to listen on all IP addresses, including those capable of accepting remote communications. |
Solution
No solution given by the vendor.
Workaround
Illumina recommends using the UCS Vulnerability Instructions Guide https://support.illumina.com/downloads/illumina-universal-copy-service-1-0.html based on the user’s specific system configuration to mitigate the vulnerabilities. Illumina recommends users read the instructions before downloading any software.
Thu, 16 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-01-16T21:35:22.697Z
Reserved: 2023-04-10T14:51:29.181Z
Link: CVE-2023-1968
Updated: 2024-08-02T06:05:27.076Z
Status : Modified
Published: 2023-04-28T19:15:16.647
Modified: 2024-11-21T07:40:14.970
Link: CVE-2023-1968
No data.
OpenCVE Enrichment
No data.
EUVD