ICSMA-26-146-01
·
Published 2026-05-26
·
View on CISA ICS-CERT ↗
Eppendorf BioFlo 320
CVSS 9.8
CRITICAL
Risk Summary
Successful exploitation of this vulnerability could allow an attacker to gain full access to functionality and data with the bioreactor.
CVEs (1)
Remediations
- Eppendorf has released a software update that permanently removes VNC access from the controller. Users should download and apply this update from: https://www.eppendorf.com/software-downloads.
- All affected BioFlo 320 systems always shipped with Virtual Network Computing (VNC) disabled by default, and VNC can only be enabled locally at the tower. Eppendorf has removed VNC configuration information from all current documentation, so it no longer appears in BioFlo 320 Operating Manuals.
- Eppendorf recommends user do the following:
- Verify that VNC is disabled on the controller
- Enable security so that only Admin and Supervisor roles can change VNC settings.
- Install Version 5.0 Software as soon as possible
Affected Vendors
Eppendorf
Affected Products (1)
Eppendorf
·
BioFlo 320 Bioreactor
vers:all/*
Affected Sectors
Healthcare and Public Health
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more