PT-2023-2562 · Illumina · Illumina Universal Copy Service

Published

2023-04-27

·

Updated

2023-05-09

·

CVE-2023-1966

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Illumina Universal Copy Service versions v1.x through v2.x
Description The issue is related to unnecessary privileges in the Illumina Universal Copy Service, which could allow an unauthenticated malicious actor to upload and execute code remotely at the operating system level. This could enable an attacker to change settings, configurations, software, or access sensitive data on the affected product. The vulnerability is also associated with errors in managing privileges, potentially allowing a remote attacker to disclose protected information and upload or execute code with elevated privileges.
Recommendations For Illumina Universal Copy Service versions v1.x through v2.x, consider disabling remote code execution capabilities until a patch is available. Restrict access to sensitive data and configurations to minimize the risk of exploitation. Avoid using the service for uploading or executing code from untrusted sources. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-02377
CVE-2023-1966

Affected Products

Illumina Universal Copy Service