illumina CVE Vulnerabilities & CVE List (7)

Products (CPE): — CVEs: 7

illumina vulnerability overview

Aggregates CVE and security vulnerability intelligence across all illumina-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk path handling; exposure may include vendor impact file overwrite in vendor surface software deployment and vendor surface production workloads contexts.

Vulnerability distribution trend (last 24 months)

Showing 17 of 7 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-1968 Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An unauthenticated malicious actor could use UCS to listen on all IP addresses, including those capable of accepting remote communications. [email protected] 10.0 0.15% 2023-04-28 2024-11-21
CVE-2023-1966 Instruments with Illumina Universal Copy Service v1.x and v2.x contain an unnecessary privileges vulnerability. An unauthenticated malicious actor could upload and execute code remotely at the operating system level, which could allow an attacker to change settings, configurations, software, or access sensitive data on the affected product. [email protected] 7.4 0.29% 2023-04-28 2024-11-21
CVE-2022-1524 LRM version 2.4 and lower does not implement TLS encryption. A malicious actor can MITM attack sensitive data in-transit, including credentials. [email protected] 7.4 0.05% 2022-06-24 2024-11-21
CVE-2022-1521 LRM does not implement authentication or authorization by default. A malicious actor can inject, replay, modify, and/or intercept sensitive data. [email protected] 9.1 0.24% 2022-06-24 2024-11-21
CVE-2022-1519 LRM does not restrict the types of files that can be uploaded to the affected product. A malicious actor can upload any file type, including executable code that allows for a remote code exploit. [email protected] 10.0 0.27% 2022-06-24 2024-11-21
CVE-2022-1518 LRM contains a directory traversal vulnerability that can allow a malicious actor to upload outside the intended directory structure. [email protected] 10.0 0.31% 2022-06-24 2024-11-21
CVE-2022-1517 LRM utilizes elevated privileges. An unauthenticated malicious actor can upload and execute code remotely at the operating system level, which can allow an attacker to change settings, configurations, software, or access sensitive data on the affected produc. An attacker could also exploit this vulnerability to access APIs not intended for general use and interact through the network. [email protected] 10.0 0.55% 2022-06-24 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence