CVE-2023-1966
Estado: ModificadaCrítica (9.8)—
Instruments with Illumina Universal Copy Service v1.x and v2.x contain an unnecessary privileges vulnerability. An unauthenticated malicious actor could upload and execute code remotely at the operating system level, which could allow an attacker to change settings, configurations, software, or access sensitive data on the affected product.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.92%
- Percentil entre todas las CVEs puntuadas: 59
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (11)
Illumina — Iscan FirmwareIllumina — Iseq 100 FirmwareIllumina — Miniseq FirmwareIllumina — Miseq FirmwareIllumina — Miseqdx FirmwareIllumina — Nextseq 1000 FirmwareIllumina — Nextseq 2000 FirmwareIllumina — Nextseq 500 FirmwareIllumina — Nextseq 550 FirmwareIllumina — Nextseq 550dx FirmwareIllumina — Novaseq 6000 Firmware
CWE
- CWE-250
- CWE-269
Referencias
- https://support.illumina.com/downloads/illumina-universal-copy-service-1-0.html
- https://www.cisa.gov/news-events/ics-medical-advisories/icsma-23-117-01
- https://support.illumina.com/downloads/illumina-universal-copy-service-1-0.html
- https://www.cisa.gov/news-events/ics-medical-advisories/icsma-23-117-01
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-1966",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-1966",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-01-16T20:30:42.910219Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 7.4,
"attackVector": "PHYSICAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 0.7
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "ics-cert@hq.dhs.gov",
"affectedData": [
{
"vendor": "Illumina ",
"product": "iScan Control Software",
"versions": [
{
"status": "affected",
"version": "4.0.0"
},
{
"status": "affected",
"version": "4.0.5"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Illumina ",
"product": "MiniSeq Control Software",
"versions": [
{
"status": "affected",
"version": "2.0 "
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Illumina ",
"product": "iSeq 100",
"versions": [
{
"status": "affected",
"version": "All versions"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Illumina ",
"product": "MiSeq Control Software",
"versions": [
{
"status": "affected",
"version": "4.0 (RUO Mode)"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Illumina ",
"product": "MiSeqDx Operating Software",
"versions": [
{
"status": "affected",
"version": "4.0.1 "
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Illumina ",
"product": "NextSeq 500/550 Control Software",
"versions": [
{
"status": "affected",
"version": "4.0"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Illumina ",
"product": "NextSeq 550Dx Control Software",
"versions": [
{
"status": "affected",
"version": "4.0 (RUO Mode)"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Illumina ",
"product": "NextSeq 550Dx Operating Software",
"versions": [
{
"status": "affected",
"version": "1.0.0 ",
"versionType": "custom",
"lessThanOrEqual": "1.3.1"
},
{
"status": "affected",
"version": "1.3.3 "
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Illumina ",
"product": "NextSeq 1000/2000 Control Software",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "1.4.1"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Illumina ",
"product": "NovaSeq 6000 Control Software",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "1.7 "
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Illumina ",
"product": "NovaSeq Control Software",
"versions": [
{
"status": "affected",
"version": "1.8"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2023-04-28T19:15:16.573",
"references": [
{
"url": "https://support.illumina.com/downloads/illumina-universal-copy-service-1-0.html",
"tags": [
"Vendor Advisory"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-23-117-01",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://support.illumina.com/downloads/illumina-universal-copy-service-1-0.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-23-117-01",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"description": [
{
"lang": "en",
"value": "CWE-250"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-269"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Instruments with Illumina Universal Copy Service v1.x and\nv2.x contain an unnecessary privileges vulnerability. An unauthenticated\nmalicious actor could upload and execute code remotely at the operating system\nlevel, which could allow an attacker to change settings, configurations,\nsoftware, or access sensitive data on the affected product.\n\n\n\n\n\n"
}
],
"lastModified": "2026-06-17T05:29:09.353",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:illumina:iscan_firmware:4.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B5000279-D40B-4526-B911-9E0641736EE1"
},
{
"criteria": "cpe:2.3:o:illumina:iscan_firmware:4.0.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BD7BE281-02B5-4B87-A7E2-D0E3BB5309CF"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:illumina:iscan:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "08732A94-734B-486E-AB2C-A2E2CA3C66AE"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:illumina:iseq_100_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D22304CE-8F36-4B51-BAA2-E2C564C04CDF"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:illumina:iseq_100:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "0136ED72-BF05-404D-910A-DA5B73F69771"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:illumina:miniseq_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E4B7C1F7-D185-4C72-B23C-A21103267CD6",
"versionStartIncluding": "2.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:illumina:miniseq:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2DA69772-E795-4A64-A6A1-0BDD503D263B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:illumina:miseq_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CC028805-6ED3-455B-8F4C-95A8B8C5E756",
"versionStartIncluding": "4.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:illumina:miseq:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8AFB0D5A-AF5A-4A84-963F-C6307ADCFF4E"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:illumina:miseqdx_firmware:*:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E97A49E3-4B87-4FE5-8FD4-5B36C61A0650",
"versionStartIncluding": "4.0.1"
},
{
"criteria": "cpe:2.3:o:illumina:miseqdx_firmware:4.0:*:*:*:ruo:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BE1CBD4E-42B1-42C6-9B3F-4F715A5DBF6D"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:illumina:miseqdx:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "CBD56D9E-B16C-4ED4-A2E4-E73A3A9A599B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:illumina:nextseq_500_firmware:4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "22E34BB5-591C-4889-851E-9A66212C8B8C"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:illumina:nextseq_500:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1C7AEA5A-707D-4BF4-9DF6-BDE6E6D97B60"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:illumina:nextseq_550_firmware:4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D0D02B5D-7E8A-41CD-BE27-5B012BE5C016"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:illumina:nextseq_550:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BF742B4D-0FC5-443A-8040-7B0A1B298707"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:illumina:nextseq_550dx_firmware:*:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "93DC004D-271D-4075-9828-E88CD7FFC403",
"versionEndIncluding": "1.3.1",
"versionStartIncluding": "1.0.0"
},
{
"criteria": "cpe:2.3:o:illumina:nextseq_550dx_firmware:*:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E199B789-BF31-40AC-B15E-31A97257002B",
"versionStartIncluding": "1.3.3"
},
{
"criteria": "cpe:2.3:o:illumina:nextseq_550dx_firmware:4.0:*:*:*:ruo:*:*:*",
"vulnerable": true,
"matchCriteriaId": "78D581A6-38A5-4F0A-A5CB-B25A9337EE78"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:illumina:nextseq_550dx:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B3D5AB9D-7EAA-45F2-A10F-A2D142B20D3D"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:illumina:nextseq_1000_firmware:1.4.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "94B82675-AA38-4584-82BD-9C376F80EA49"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:illumina:nextseq_1000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "93589C3C-F577-4C67-962F-166E28911ED2"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:illumina:nextseq_2000_firmware:1.4.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6671E6F8-85D5-4970-98FE-6189C8F98852"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:illumina:nextseq_2000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "753D8FDF-5D25-46B9-8E66-30FB8E8A9A87"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:illumina:novaseq_6000_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3A429D26-AF22-4AC2-AB02-76C72B9B9B05",
"versionEndIncluding": "1.7"
},
{
"criteria": "cpe:2.3:o:illumina:novaseq_6000_firmware:1.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B4C702B1-4BAD-4E32-9659-D9F5C3F2F922"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:illumina:novaseq_6000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "0D879686-89E7-4152-AEF9-DC8A33FDA4A5"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "ics-cert@hq.dhs.gov"
}