CVE-2022-1517

CRITICAL

Illumina Local Run Manager 1.3 to 3.1 - Unauthenticated Remote Code Execution

Title source: manual
STIX 2.1

Description

LRM utilizes elevated privileges. An unauthenticated malicious actor can upload and execute code remotely at the operating system level, which can allow an attacker to change settings, configurations, software, or access sensitive data on the affected produc. An attacker could also exploit this vulnerability to access APIs not intended for general use and interact through the network.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://www.cisa.gov/uscert/ics/advisories/icsa-22-153-02

Scores

CVSS v3 10.0
EPSS 0.0140
EPSS Percentile 69.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-269 CWE-250
Status published
Products (1)
illumina/local_run_manager 1.3 - 3.1
Published Jun 24, 2022
Tracked Since Feb 18, 2026