CVE-2026-17583
Received Received - Intake

Tampering in Thermo Fisher Applied Biosystems Genetic Analyzers

Vulnerability report for CVE-2026-17583, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: ICS-CERT

Description

The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-06
AI Q&A
2026-08-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
thermo_fisher applied_biosystems_genetic_analyzers *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-353 The product uses a transmission protocol that does not include a mechanism for verifying the integrity of the data during transmission, such as a checksum.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Thermo Fisher Applied Biosystems Genetic Analyzers. The issue is that output files with .fsa or .hid extensions can be edited. An attacker could modify these files to alter DNA data, leading to inaccurate DNA test results.

Detection Guidance

Detecting tampered .fsa/.hid output files requires manual inspection of file metadata and content. Compare file hashes with known good samples, check for unusual timestamps, and verify digital signatures if used. No automated commands are provided in the context.

Impact Analysis

This vulnerability could lead to incorrect DNA test outcomes, which may cause misdiagnosis, improper treatment, or legal issues if the tampered data is used in forensic or medical contexts. It undermines the integrity of genetic analysis results.

Compliance Impact

This vulnerability could violate compliance with standards like GDPR and HIPAA by compromising the integrity and accuracy of genetic data. Tampered DNA results may lead to unauthorized processing or disclosure of sensitive health information, violating regulatory requirements.

Mitigation Strategies

Restrict access to .fsa/.hid output files, implement file integrity monitoring, and validate DNA data through secondary methods. Ensure physical and network security for genetic analyzers to prevent unauthorized file modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17583. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart