← Back to browse · API

CVE-2022-1519

Severity
CRITICAL
CVSS
10.0
EPSS
0.01266
Risk score
40.44
CISA KEV
No
PoC
No
Published
2022-06-24
Modified
2025-04-16
First seen
2026-08-07
Aliases
EUVD-2022-24817, GHSA-4PG3-X42Q-599H
Products
Illumina:MiSeq Dx LRM Versions 1.3 to 3.1, Illumina:MiSeq Instrument LRM Versions 1.3 to 3.1, Illumina:MiniSeq Instrument LRM Versions 1.3 to 3.1, Illumina:NextSeq 500 Instrument LRM Versions 1.3 to 3.1, Illumina:NextSeq 550 Instrument LRM Versions 1.3 to 3.1, Illumina:NextSeq 550Dx LRM Versions 1.3 to 3.1, Illumina:iSeq 100 Instrument LRM Versions 1.3 to 3.1
Sources
euvd EUVD-2022-24817

Description

LRM does not restrict the types of files that can be uploaded to the affected product. A malicious actor can upload any file type, including executable code that allows for a remote code exploit.

References