Thermo Fisher Applied Biosystems Genetic Analyzers Missing Support for Integrity Check

Summary

CVECVE-2026-17583
StatePUBLISHED
Assignericscert
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-05 21:16:57 UTC
Updated2026-08-05 21:16:57 UTC
DescriptionThe affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes.

Risk And Classification

Primary CVSS: v4.0 8.3 HIGH from [email protected]

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Problem Types: CWE-353 | CWE-353 CWE-353


VersionSourceTypeScoreSeverityVector
4.0[email protected]Secondary8.3HIGHCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:N/E:X/C...
4.0CNACVSS8.3HIGHCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:N
3.1[email protected]Secondary8.4HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
3.1CNACVSS8.4HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v4.0 Breakdown

Attack Vector
Local
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Confidentiality
None
Integrity
High
Availability
High
Sub Conf.
None
Sub Integrity
High
Sub Availability
None

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CVSS v3.1 Breakdown

Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Thermo Fisher Applied Biosystems 3500/3500xL Series Data Collection Software affected 4.0.2 custom Not specified
CNA Thermo Fisher Applied Biosystems 3730/3730xL Series Data Collection Software affected 5.0.2 custom Not specified
CNA Thermo Fisher Applied Biosystems SeqStudio Genetic Analyzer Data Collection Software affected 1.2.5 custom Not specified
CNA Thermo Fisher Applied Biosystems SeqStudio Flex Series Instrument Software affected 1.2.0 custom Not specified
CNA Thermo Fisher Applied Biosystems GeneMapper ID-X Software affected 1.7.3 custom Not specified
CNA Thermo Fisher Applied Biosystems 3130 Series Data Collection Software affected 4.1 custom Not specified
CNA Thermo Fisher ABI PRISM 3100/3100-Avant Data Collection Software affected 2.0 custom Not specified
CNA Thermo Fisher ABI PRISM 310 Data Collection Software affected 3.1 custom Not specified

References

ReferenceSourceLinkTags
www.cisa.gov/news-events/ics-medical-advisories/icsma-26-216-01 [email protected] www.cisa.gov
www.cve.org/CVERecord [email protected] www.cve.org
documents.thermofisher.com/TFS-Assets/CORP/Product-Guides/fsa_hid_bulletin.pdf [email protected] documents.thermofisher.com
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Vendor Comments And Credit

Discovery Credit

CNA: Nathaniel Adams, Laura Gaydosh-Combs, and Kevin Dyer reported this vulnerability to CISA. (en)

Additional Advisory Data

Solutions

CNA: Thermo Fisher has developed security updates to address the vulnerability. The security updates implement the use of digital signatures on the instrument software that adds an extralayer of protection. Moving forward, this will help users verify that data files have not been modified. Applied Biosystems 3500/3500xL Series Data Collection Software: Update to version 4.0.3 https://downloads.thermofisher.com/3500_DCS_v4.0.3_Patch/v4.0.3_Patch_Installer.exe Applied Biosystems 3730/3730xL Series Data Collection Software: Update to version 5.0.3 https://downloads.thermofisher.com/3730xl_UDC_v5.0.3_Patch/3730xl_UDC_v5.0.3_Patch.exe Applied Biosystems SeqStudio Genetic Analyzer Data Collection Software: Update to version 1.2.6 https://downloads.thermofisher.com/SeqStudio/1.2.6/SeqStudio-1.2.6.abpkg Applied Biosystems SeqStudio Flex Series Instrument Software: Update to version 1.2.1 https://downloads.thermofisher.com/SeqStudioFlex/1.2.1/SeqStudioFlex-1.2.1.abpkg Applied Biosystems GeneMapper ID-X Software: Update to version 1.7.4 https://downloads.thermofisher.com/GeneMapperID-Xv1.7.4_Patch/GMIDX_v1.7.4_Patch.exe

Workarounds

CNA: Applied Biosystems 3130 Series Data Collection Software: Product is End of Life (EoL), no update provided ABI PRISM 3100/3100-Avant Data Collection Software: Product is End of Life (EoL), no update provided ABI PRISM 310 Data Collection Software: Product is End of Life (EoL), no update provided For users who are unable to immediately implement all applicable security updates, Thermo Fisher Scientific recommends implementing the following interim mitigation measures until the applicable updates have been installed:  * Maintain a secure chain of custody for files generated by the HID instrumentation throughout the analysis workflow. * Store generated files on encrypted, password-protected storage media (for example, encrypted USB drives or encrypted hard drives). * Restrict access to generated files to authorized personnel in accordance with your laboratory's access control policies. * Apply the principle of least privilege by limiting user permissions on systems operating the HID instrumentation or hosting associated data analysis and secondary analysis software. * Leverage firewall rules and network access control lists (NACLs) to restrict internet connectivity to only trusted sources. For more information, refer to Thermo Fisher's security bulletin. https://documents.thermofisher.com/TFS-Assets/CORP/Product-Guides/fsa_hid_bulletin.pdf

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report