← Back to browse · API

CVE-2023-1968

Severity
CRITICAL
CVSS
10.0
EPSS
0.01812
Risk score
40.63
CISA KEV
No
PoC
No
Published
2023-04-28
Modified
2025-01-16
First seen
2026-08-07
Aliases
EUVD-2023-24154, GHSA-CPWH-2GHX-4JVR
Products
Illumina:MiSeq Control Software 4.0 (RUO Mode), Illumina:MiSeqDx Operating Software 4.0.1, Illumina:MiniSeq Control Software 2.0, Illumina:NextSeq 1000/2000 Control Software 0 ≤1.4.1, Illumina:NextSeq 500/550 Control Software 4.0, Illumina:NextSeq 550Dx Control Software 4.0 (RUO Mode), Illumina:NextSeq 550Dx Operating Software 1.0.0 ≤1.3.1, Illumina:NextSeq 550Dx Operating Software 1.3.3, Illumina:NovaSeq 6000 Control Software 0 ≤1.7, Illumina:NovaSeq Control Software 1.8, Illumina:iScan Control Software 4.0.0, Illumina:iScan Control Software 4.0.5, Illumina:iSeq 100 All versions
Sources
euvd EUVD-2023-24154

Description

Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An unauthenticated malicious actor could use UCS to listen on all IP addresses, including those capable of accepting remote communications.

References