9.8

CVE-2023-1966

Instruments with Illumina Universal Copy Service v1.x and
v2.x contain an unnecessary privileges vulnerability. An unauthenticated
malicious actor could upload and execute code remotely at the operating system
level, which could allow an attacker to change settings, configurations,
software, or access sensitive data on the affected product.





Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IlluminaIscan Firmware Version4.0.0
   IlluminaIscan Version-
IlluminaIscan Firmware Version4.0.5
   IlluminaIscan Version-
IlluminaIseq 100 Firmware
   IlluminaIseq 100 Version-
IlluminaMiniseq Firmware Version >= 2.0
   IlluminaMiniseq Version-
IlluminaMiseq Firmware Version >= 4.0
   IlluminaMiseq Version-
IlluminaMiseqdx Firmware SwEdition- Version >= 4.0.1
   IlluminaMiseqdx Version-
IlluminaMiseqdx Firmware Version4.0 SwEditionruo
   IlluminaMiseqdx Version-
IlluminaNextseq 500 Firmware Version4.0
   IlluminaNextseq 500 Version-
IlluminaNextseq 550 Firmware Version4.0
   IlluminaNextseq 550 Version-
IlluminaNextseq 550dx Firmware SwEdition- Version >= 1.0.0 <= 1.3.1
   IlluminaNextseq 550dx Version-
IlluminaNextseq 550dx Firmware SwEdition- Version >= 1.3.3
   IlluminaNextseq 550dx Version-
IlluminaNextseq 550dx Firmware Version4.0 SwEditionruo
   IlluminaNextseq 550dx Version-
IlluminaNextseq 1000 Firmware Version1.4.1
   IlluminaNextseq 1000 Version-
IlluminaNextseq 2000 Firmware Version1.4.1
   IlluminaNextseq 2000 Version-
IlluminaNovaseq 6000 Firmware Version <= 1.7
   IlluminaNovaseq 6000 Version-
IlluminaNovaseq 6000 Firmware Version1.8
   IlluminaNovaseq 6000 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.522
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ics-cert@hq.dhs.gov 7.4 0.7 6
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-250 Execution with Unnecessary Privileges

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.