CVE Vulnerabilities

CVE-2023-1966

Improper Privilege Management

Published: Apr 28, 2023 | Modified: May 09, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Instruments with Illumina Universal Copy Service v1.x and v2.x contain an unnecessary privileges vulnerability. An unauthenticated malicious actor could upload and execute code remotely at the operating system level, which could allow an attacker to change settings, configurations, software, or access sensitive data on the affected product.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Iscan_firmware Illumina 4.0.0 (including) 4.0.0 (including)
Iscan_firmware Illumina 4.0.5 (including) 4.0.5 (including)

Potential Mitigations

References