CVE-2024-35585
Received Received - Intake

Authentication Bypass in Oxford Nanopore MinKNOW

Vulnerability report for CVE-2024-35585, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: MITRE

Description

Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
oxford_nanopore mindknow to 24.11 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2024-35585 involves Oxford Nanopore MinKNOW software relying solely on a client's source IP address for authentication. This means the software does not verify the client's identity beyond the IP address, which can be spoofed or manipulated. The vulnerability allows unauthorized access or control of the sequencing device if an attacker can impersonate a trusted IP address.

Impact Analysis

This vulnerability could allow attackers to bypass authentication and gain unauthorized access to MinKNOW, potentially leading to data manipulation, sequencing operations disruption, or denial-of-service conditions. Attackers might execute unauthorized commands, steal sensitive data, or prevent the device from functioning properly.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating compliance requirements under GDPR and HIPAA. GDPR mandates strict data protection and access controls, while HIPAA requires safeguards for protected health information. A breach could result in legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Upgrade MinKNOW to version 24.06 or later. Disable Remote Connect unless necessary and restrict it to trusted networks. Implement endpoint protection with antivirus and malware scanning tools.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2024-35585. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart