Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An unauthenticated malicious actor could use UCS to listen on all IP addresses, including those capable of accepting remote communications.







Project Subscriptions

Vendors Products
Illumina Subscribe
Iscan Firmware Subscribe
Iseq 100 Subscribe
Iseq 100 Firmware Subscribe
Miniseq Subscribe
Miniseq Firmware Subscribe
Miseq Firmware Subscribe
Miseqdx Subscribe
Miseqdx Firmware Subscribe
Nextseq 1000 Subscribe
Nextseq 1000 Firmware Subscribe
Nextseq 2000 Subscribe
Nextseq 2000 Firmware Subscribe
Nextseq 500 Subscribe
Nextseq 500 Firmware Subscribe
Nextseq 550 Subscribe
Nextseq 550 Firmware Subscribe
Nextseq 550dx Subscribe
Nextseq 550dx Firmware Subscribe
Novaseq 6000 Subscribe
Novaseq 6000 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-24154 Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An unauthenticated malicious actor could use UCS to listen on all IP addresses, including those capable of accepting remote communications.
Fixes

Solution

No solution given by the vendor.


Workaround

Illumina recommends using the UCS Vulnerability Instructions Guide https://support.illumina.com/downloads/illumina-universal-copy-service-1-0.html  based on the user’s specific system configuration to mitigate the vulnerabilities. Illumina recommends users read the instructions before downloading any software.

History

Thu, 16 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-01-16T21:35:22.697Z

Reserved: 2023-04-10T14:51:29.181Z

Link: CVE-2023-1968

cve-icon Vulnrichment

Updated: 2024-08-02T06:05:27.076Z

cve-icon NVD

Status : Modified

Published: 2023-04-28T19:15:16.647

Modified: 2024-11-21T07:40:14.970

Link: CVE-2023-1968

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.