PT-2022-4354 · Illumina · Illumina Local Run Manager

Published

2022-06-24

·

Updated

2022-07-01

·

CVE-2022-1524

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Illumina Local Run Manager versions 2.4 and lower
Description The issue is related to the lack of TLS encryption in the implementation of protocols, allowing a malicious actor to perform a man-in-the-middle (MITM) attack on sensitive data in-transit, including credentials. This can compromise the confidentiality of protected information.
Recommendations For versions 2.4 and lower, consider disabling sensitive data transmission until a patch that implements TLS encryption is available. Restrict access to sensitive data to minimize the risk of exploitation. As a temporary workaround, avoid transmitting credentials or other sensitive information using the affected software until a fix is implemented.

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-05214
CVE-2022-1524

Affected Products

Illumina Local Run Manager