Impact
Thermo Fisher Applied Biosystems Genetic Analyzers lack integrity checks for .fsa/.hid output files, enabling an attacker to modify files after they are created. Such tampering can change DNA sequence data read by the analyzer, producing incorrect test results and potentially leading to wrong clinical or forensic conclusions.
Affected Systems
Affected products include Thermo Fisher Applied Biosystems 3500/3500xL Series Data Collection Software (fixed in version 4.0.3), 3730/3730xL Series Data Collection Software (fixed in 5.0.3), SeqStudio Genetic Analyzer Data Collection Software (fixed in 1.2.6), SeqStudio Flex Series Instrument Software (fixed in 1.2.1), and GeneMapper ID‑X Software (fixed in 1.7.4). End‑of‑life products such as 3130 Series, ABI PRISM 3100/3100‑Avant, and ABI PRISM 310 have no updates available.
Risk and Exploitability
The CVSS score of 8.3 reflects high severity; EPSS is not available and the vulnerability is not listed in CISA KEV, suggesting no confirmed public exploitation yet. Exploitation requires the ability to locate and edit .fsa/.hid files, implying local or privileged access to the instrument or the storage where output files reside. An insider or compromised system could use simple file‑editing tools to alter data, after which the analyzer would read the tampered file and generate incorrect DNA interpretation.
OpenCVE Enrichment