CISA has warned of several security
flaws
in DNA sequencing medical devices.
The security issues could enable hackers to spy on network traffic and change genomic data results.
The issues impact the Universal Copy Service software in the following instruments:
-
- Illumina MiSeqDx,
- NextSeq 550Dx,
- iScan, iSeq 100,
- MiniSeq, MiSeq,
- NextSeq 500,
- NextSeq 550,
- NextSeq 1000/2000,
- and NovaSeq 6000.
- The severe security flaw that was tracked is CVE-2023-1968. The flaw, with a CVSS score of 10.0, could allow hackers to spy on network traffic and deploy remote commands.
- The second flaw that was found is CVE-2023-1966. The flaw, with a CVSS score of 7.5, could allow hackers to manipulate login privileges.
- In what is likely the worst-case scenario, the FDA stated that hackers could use this flaw to manipulate genomic data results in the instruments.