CVE-2023-1966 is a critical unnecessary privileges vulnerability affecting Illumina Universal Copy Service v1.x and v2.x, found in their DNA sequencing instruments. This flaw allows an unauthenticated attacker to remotely execute code at the operating system level. With a CVSS score of 9.8 (CRITICAL), the vulnerability has a network attack vector, low attack complexity, and can lead to complete compromise of confidentiality, integrity, and availability, enabling unauthorized changes to settings, configurations, software, or access to sensitive data. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community attention with 14 mentions and 3 media articles, indicating high awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0.0CPE matchmatch criteria | cpe:2.3:o:illumina:iscan_firmware:4.0.0:*:*:*:*:*:*:* | ||
4.0.5CPE matchmatch criteria | cpe:2.3:o:illumina:iscan_firmware:4.0.5:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:illumina:iseq_100_firmware:*:*:*:*:*:*:*:* | ||
>= 2.0CPE matchmatch criteria | cpe:2.3:o:illumina:miniseq_firmware:*:*:*:*:*:*:*:* | ||
>= 4.0CPE matchmatch criteria | cpe:2.3:o:illumina:miseq_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.