nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-1968 CVE-2023-1968
CRITICAL
CVE-2023-1968
Record summary
CVE-2023-1968 has a selected CVSS score of 10.0 (critical).
Description
Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An unauthenticated malicious actor could use UCS to listen on all IP addresses, including those capable of accepting remote communications.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 16, 2025 · Source: CVE List
Affected products and versions
11| Product | Source | Version range | Status |
|---|---|---|---|
MiSeq Control SoftwareBrowse Illumina / MiSeq Control SoftwareDefault status: unaffected | CVE List | 4.0 (RUO Mode) | affected |
MiSeqDx Operating SoftwareBrowse Illumina / MiSeqDx Operating SoftwareDefault status: unaffected | CVE List | 4.0.1 | affected |
MiniSeq Control SoftwareBrowse Illumina / MiniSeq Control SoftwareDefault status: unaffected | CVE List | 2.0 | affected |
NextSeq 1000/2000 Control SoftwareBrowse Illumina / NextSeq 1000/2000 Control SoftwareDefault status: unaffected | CVE List | Through 1.4.1 | affected |
NextSeq 500/550 Control SoftwareBrowse Illumina / NextSeq 500/550 Control SoftwareDefault status: unaffected | CVE List | 4.0 | affected |
NextSeq 550Dx Control SoftwareBrowse Illumina / NextSeq 550Dx Control SoftwareDefault status: unaffected | CVE List | 4.0 (RUO Mode) | affected |
NextSeq 550Dx Operating SoftwareBrowse Illumina / NextSeq 550Dx Operating SoftwareDefault status: unaffected | CVE List | 1.0.0 to ≤ 1.3.1 | affected |
| 1.3.3 | affected | ||
NovaSeq 6000 Control SoftwareBrowse Illumina / NovaSeq 6000 Control SoftwareDefault status: unaffected | CVE List | Through 1.7 | affected |
NovaSeq Control SoftwareBrowse Illumina / NovaSeq Control SoftwareDefault status: unaffected | CVE List | 1.8 | affected |
iScan Control SoftwareBrowse Illumina / iScan Control SoftwareDefault status: unaffected | CVE List | 4.0.0 | affected |
| 4.0.5 | affected | ||
iSeq 100Browse Illumina / iSeq 100Default status: unaffected | CVE List | All versions | affected |
References
3support.illumina.comVendor advisory
https://support.illumina.com/downloads/illumina-universal-copy-service-1-0.html cisa.gov
https://www.cisa.gov/news-events/ics-medical-advisories/icsma-23-117-01