← Back to home
ICSA-22-153-02  ·  Published 2022-08-23  ·  View on CISA ICS-CERT ↗

Illumina Local Run Manager

CVSS 10.0 CRITICAL

Risk Summary

Successful exploitation of these vulnerabilities may allow an unauthenticated malicious actor to take control of the affected product remotely and take any action at the operating system level. An attacker could impact settings, configurations, software, or data on the affected product and interact through the affected product with the connected network..

Remediations

  • Illumina has developed a software patch to protect against the remote exploitation of these vulnerabilities and is actively working to provide a permanent software fix for current and future instruments.
  • For instruments connected to the Internet, the software patch is available for download.
  • Illumnia has released the following hashes for the Local Run Manager in its latest software patch: Filename: LocalRunManagerSecurityPatch.msi
  • SHA-512: 52b5cfdc462b10011027e94f184c2f0da25b0b1363fddb7fa5793938d11f976259a7f73e77c2fd157f560439ec3df70446aa561b586dc8ef94db2ed95fcce841
  • SHA-256: 595b724f1c5b4bac446001400b38b748b4ef05520b5489ea4711a2a4289e721a
  • SHA-1: 25e523031b3bd818d4bba1017c534c735f650e23
  • MD5: 4552a1130947b95ac18be4335c1447f5
  • For affected products not connected to the Internet, Illumina has developed other options for the installation of the software patch. Please contact Illumina Tech Support at [email protected] to obtain information about these options.

Affected Vendors

Illumina

Affected Products (7)

Illumina · iSeq 100 Instrument LRM >= 1.3 | <= 3.1
Illumina · MiniSeq Instrument LRM >= 1.3 | <= 3.1
Illumina · MiSeq Dx LRM >= 1.3 | <= 3.1
Illumina · MiSeq Instrument LRM >= 1.3 | <= 3.1
Illumina · NextSeq 500 Instrument LRM >= 1.3 | <= 3.1
Illumina · NextSeq 550 Instrument LRM >= 1.3 | <= 3.1
Illumina · NextSeq 550Dx LRM >= 1.3 | <= 3.1

Affected Sectors

Healthcare and Public Health

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more