CVE-2022-1517
CRITICALIllumina Local Run Manager 1.3 to 3.1 - Unauthenticated Remote Code Execution
Title source: manualDescription
LRM utilizes elevated privileges. An unauthenticated malicious actor can upload and execute code remotely at the operating system level, which can allow an attacker to change settings, configurations, software, or access sensitive data on the affected produc. An attacker could also exploit this vulnerability to access APIs not intended for general use and interact through the network.
References (1)
Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://www.cisa.gov/uscert/ics/advisories/icsa-22-153-02
Scores
CVSS v3
10.0
EPSS
0.0140
EPSS Percentile
69.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-269
CWE-250
Status
published
Products (1)
illumina/local_run_manager
1.3 - 3.1
Published
Jun 24, 2022
Tracked Since
Feb 18, 2026