10

CVE-2023-1968

Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An unauthenticated malicious actor could use UCS to listen on all IP addresses, including those capable of accepting remote communications. 







Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IlluminaIscan Firmware Version4.0.0
   IlluminaIscan Version-
IlluminaIscan Firmware Version4.0.5
   IlluminaIscan Version-
IlluminaIseq 100 Firmware
   IlluminaIseq 100 Version-
IlluminaMiniseq Firmware Version >= 2.0
   IlluminaMiniseq Version-
IlluminaMiseq Firmware Version >= 4.0
   IlluminaMiseq Version-
IlluminaMiseqdx Firmware SwEdition- Version >= 4.0.1
   IlluminaMiseqdx Version-
IlluminaMiseqdx Firmware Version4.0 SwEditionruo
   IlluminaMiseqdx Version-
IlluminaNextseq 500 Firmware Version4.0
   IlluminaNextseq 500 Version-
IlluminaNextseq 550 Firmware Version4.0
   IlluminaNextseq 550 Version-
IlluminaNextseq 550dx Firmware SwEdition- Version >= 1.0.0 <= 1.3.1
   IlluminaNextseq 550dx Version-
IlluminaNextseq 550dx Firmware SwEdition- Version >= 1.3.3
   IlluminaNextseq 550dx Version-
IlluminaNextseq 550dx Firmware Version4.0 SwEditionruo
   IlluminaNextseq 550dx Version-
IlluminaNextseq 1000 Firmware Version1.4.1
   IlluminaNextseq 1000 Version-
IlluminaNextseq 2000 Firmware Version1.4.1
   IlluminaNextseq 2000 Version-
IlluminaNovaseq 6000 Firmware Version <= 1.7
   IlluminaNovaseq 6000 Version-
IlluminaNovaseq 6000 Firmware Version1.8
   IlluminaNovaseq 6000 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.386
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
ics-cert@hq.dhs.gov 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-1327 Binding to an Unrestricted IP Address

The product assigns the address 0.0.0.0 for a database server, a cloud service/instance, or any computing resource that communicates remotely.