Illumina Universal Copy Service Vulnerabilities
Vulnerabilities in Illumina Universal Copy Service could allow a remote attack to take control of affected devices
Summary
Vulnerabilities in Illumina Universal Copy Service could allow a remote attack to take control of affected devices
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Illumina has disclosed two vulnerabilities in the Universal Copy Service software, which is used in a range of medical devices. The vulnerability classified as CVE-2023-1968 has been assigned a CVSSv3 base score of 10.0, and involves binding to unrestricted IP addresses. An unauthenticated, attacker could use this vulnerability to listen on all IP addresses, including those capable of accepting remote communications.
The second vulnerability, classified as CVE-2023-1966, involves unnecessary privileges being in place on devices operating Illumina Universal Copy Service v1.x and v2.x. An unauthenticated attacker could upload and execute code remotely at the operating system level, which could allow an attacker to change settings, configurations, software, or access sensitive data on the affected product.
Remediation advice
Affected organisations are encouraged to review the Illumina Universal Copy Service Vulnerability Security Advisory and apply the relevant security updates or mitigations, which include configuring account credentials.
The US Cyber Security and Infrastructure Agency (CISA) has also released a medical advisory classified ICSMA-23-117-01.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 28 April 2023 2:51 pm