ICSA-22-153-02
·
Published 2022-08-23
·
View on CISA ICS-CERT ↗
Illumina Local Run Manager
CVSS 10.0
CRITICAL
Risk Summary
Successful exploitation of these vulnerabilities may allow an unauthenticated malicious actor to take control of the affected product remotely and take any action at the operating system level. An attacker could impact settings, configurations, software, or data on the affected product and interact through the affected product with the connected network..
Remediations
- Illumina has developed a software patch to protect against the remote exploitation of these vulnerabilities and is actively working to provide a permanent software fix for current and future instruments.
- For instruments connected to the Internet, the software patch is available for download.
- Illumnia has released the following hashes for the Local Run Manager in its latest software patch: Filename: LocalRunManagerSecurityPatch.msi
- SHA-512: 52b5cfdc462b10011027e94f184c2f0da25b0b1363fddb7fa5793938d11f976259a7f73e77c2fd157f560439ec3df70446aa561b586dc8ef94db2ed95fcce841
- SHA-256: 595b724f1c5b4bac446001400b38b748b4ef05520b5489ea4711a2a4289e721a
- SHA-1: 25e523031b3bd818d4bba1017c534c735f650e23
- MD5: 4552a1130947b95ac18be4335c1447f5
- For affected products not connected to the Internet, Illumina has developed other options for the installation of the software patch. Please contact Illumina Tech Support at [email protected] to obtain information about these options.
Affected Vendors
Illumina
Affected Products (7)
Illumina
·
iSeq 100 Instrument LRM
>= 1.3 | <= 3.1
Illumina
·
MiniSeq Instrument LRM
>= 1.3 | <= 3.1
Illumina
·
MiSeq Dx LRM
>= 1.3 | <= 3.1
Illumina
·
MiSeq Instrument LRM
>= 1.3 | <= 3.1
Illumina
·
NextSeq 500 Instrument LRM
>= 1.3 | <= 3.1
Illumina
·
NextSeq 550 Instrument LRM
>= 1.3 | <= 3.1
Illumina
·
NextSeq 550Dx LRM
>= 1.3 | <= 3.1
Affected Sectors
Healthcare and Public Health
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more