Skip to main content

Illumina Universal Copy Service Vulnerabilities

Vulnerabilities in Illumina Universal Copy Service could allow a remote attack to take control of affected devices

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Vulnerabilities in Illumina Universal Copy Service could allow a remote attack to take control of affected devices


Threat details

Introduction

Illumina has disclosed two vulnerabilities in the Universal Copy Service software, which is used in a range of medical devices. The vulnerability classified as CVE-2023-1968 has been assigned a CVSSv3 base score of 10.0, and involves binding to unrestricted IP addresses.  An unauthenticated, attacker could use this vulnerability to listen on all IP addresses, including those capable of accepting remote communications.  

The second vulnerability, classified as CVE-2023-1966, involves unnecessary privileges being in place on devices operating Illumina Universal Copy Service v1.x and v2.x. An unauthenticated attacker could upload and execute code remotely at the operating system level, which could allow an attacker to change settings, configurations, software, or access sensitive data on the affected product. 


Remediation advice

Affected organisations are encouraged to review the Illumina Universal Copy Service Vulnerability Security Advisory and apply the relevant security updates or mitigations, which include configuring account credentials.

The US Cyber Security and Infrastructure Agency (CISA) has also released a medical advisory classified ICSMA-23-117-01.



Last edited: 28 April 2023 2:51 pm