V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2023-1968
CVE
High

Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An unauthenticated malic…

CVSS
7.5
High
EPSS
0.00
p35
Published
2023-01-01
Updated
2023-01-01
Description

Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An unauthenticated malicious actor could use UCS to listen on all IP addresses, including those capable of accepting remote communications.

Tags · CWE
Pre-auth
CWE-1327
CAPEC-1
Affected products
Iscan_firmwareIseq_100_firmwareMiniseq_firmwareMiseq_firmwareMiseqdx_firmwareNextseq_1000_firmwareNextseq_2000_firmwareNextseq_500_firmwareNextseq_550_firmwareNextseq_550dx_firmwareNovaseq_6000_firmware
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Timeline
2023-01-01
Published
2023-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.001 · p35
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
iscan_firmware*Tracked
iseq_100_firmware*Tracked
miniseq_firmware*Tracked
miseq_firmware*Tracked
miseqdx_firmware*Tracked
nextseq_1000_firmware*Tracked
nextseq_2000_firmware*Tracked
nextseq_500_firmware*Tracked
nextseq_550_firmware*Tracked
nextseq_550dx_firmware*Tracked
novaseq_6000_firmware*Tracked
Source databases
CVE
Related vulnerabilities