PT-2022-4354 · Illumina · Illumina Local Run Manager
Published
2022-06-24
·
Updated
2022-07-01
·
CVE-2022-1524
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Illumina Local Run Manager versions 2.4 and lower
Description
The issue is related to the lack of TLS encryption in the implementation of protocols, allowing a malicious actor to perform a man-in-the-middle (MITM) attack on sensitive data in-transit, including credentials. This can compromise the confidentiality of protected information.
Recommendations
For versions 2.4 and lower, consider disabling sensitive data transmission until a patch that implements TLS encryption is available. Restrict access to sensitive data to minimize the risk of exploitation. As a temporary workaround, avoid transmitting credentials or other sensitive information using the affected software until a fix is implemented.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Illumina Local Run Manager