CVE-2023-1966

HIGH

Instruments with Illumina Universal Copy Service v1.x-v2.x - Privil...

Title source: llm
STIX 2.1

Description

Instruments with Illumina Universal Copy Service v1.x and v2.x contain an unnecessary privileges vulnerability. An unauthenticated malicious actor could upload and execute code remotely at the operating system level, which could allow an attacker to change settings, configurations, software, or access sensitive data on the affected product.

Scores

CVSS v3 7.4
EPSS 0.0025
EPSS Percentile 48.1%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269 CWE-250
Status published
Products (15)
illumina/iscan_firmware 4.0.0
illumina/iscan_firmware 4.0.5
illumina/iseq_100_firmware
illumina/miniseq_firmware 2.0
illumina/miseq_firmware 4.0
illumina/miseqdx_firmware 4.0
illumina/miseqdx_firmware 4.0.1
illumina/nextseq_1000_firmware 1.4.1
illumina/nextseq_2000_firmware 1.4.1
illumina/nextseq_500_firmware 4.0
... and 5 more
Published Apr 28, 2023
Tracked Since Feb 18, 2026