Impact
Oxford Nanopore MinKNOW versions prior to 24.06 authenticate clients by trusting the source IP address presented by the client. This design flaw allows an attacker who can forge or spoof a source IP within the trusted network to gain legitimate authentication without knowledge of any credentials, effectively bypassing access controls. The result is unauthorized access to the device, which could lead to disclosure of sensitive sequencing data, manipulation of sequencing parameters, or further exploitation of the device for malicious purposes. The flaw is catalogued as CWE-306, indicating improper trust of a legacy security mechanism.
Affected Systems
The vulnerability affects the Oxford Nanopore MinKNOW software prior to version 24.06. Devices running any earlier build of the software that rely on client IP for authentication are susceptible, regardless of the operating system or hardware platform the MinKNOW software is installed on.
Risk and Exploitability
The CVSS score of 8.6 reflects a high severity, and the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog, indicating no currently known public exploitation. Based on the description, the likely attack vector is local network or physically adjacent network where an attacker can spoof the source IP. Exploitation requires the ability to interact with the MinKNOW client interface and control the IP source; no additional prerequisites such as privileged credentials are required. The impact is full bypass of authentication controls to any client that can assume a trusted IP address.
OpenCVE Enrichment