The affected

Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Thermo Fisher has developed security updates to address the vulnerability. The security updates implement the use of digital signatures on the instrument software that adds an extralayer of protection. Moving forward, this will help users verify that data files have not been modified. Applied Biosystems 3500/3500xL Series Data Collection Software: Update to version 4.0.3 https://downloads.thermofisher.com/3500_DCS_v4.0.3_Patch/v4.0.3_Patch_Installer.exe Applied Biosystems 3730/3730xL Series Data Collection Software: Update to version 5.0.3 https://downloads.thermofisher.com/3730xl_UDC_v5.0.3_Patch/3730xl_UDC_v5.0.3_Patch.exe Applied Biosystems SeqStudio Genetic Analyzer Data Collection Software: Update to version 1.2.6 https://downloads.thermofisher.com/SeqStudio/1.2.6/SeqStudio-1.2.6.abpkg Applied Biosystems SeqStudio Flex Series Instrument Software: Update to version 1.2.1 https://downloads.thermofisher.com/SeqStudioFlex/1.2.1/SeqStudioFlex-1.2.1.abpkg Applied Biosystems GeneMapper ID-X Software: Update to version 1.7.4 https://downloads.thermofisher.com/GeneMapperID-Xv1.7.4_Patch/GMIDX_v1.7.4_Patch.exe


Workaround

Applied Biosystems 3130 Series Data Collection Software: Product is End of Life (EoL), no update provided ABI PRISM 3100/3100-Avant Data Collection Software: Product is End of Life (EoL), no update provided ABI PRISM 310 Data Collection Software: Product is End of Life (EoL), no update provided For users who are unable to immediately implement all applicable security updates, Thermo Fisher Scientific recommends implementing the following interim mitigation measures until the applicable updates have been installed:  * Maintain a secure chain of custody for files generated by the HID instrumentation throughout the analysis workflow. * Store generated files on encrypted, password-protected storage media (for example, encrypted USB drives or encrypted hard drives). * Restrict access to generated files to authorized personnel in accordance with your laboratory's access control policies. * Apply the principle of least privilege by limiting user permissions on systems operating the HID instrumentation or hosting associated data analysis and secondary analysis software. * Leverage firewall rules and network access control lists (NACLs) to restrict internet connectivity to only trusted sources. For more information, refer to Thermo Fisher's security bulletin. https://documents.thermofisher.com/TFS-Assets/CORP/Product-Guides/fsa_hid_bulletin.pdf

History

Wed, 05 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes.
Title Thermo Fisher Applied Biosystems Genetic Analyzers Missing Support for Integrity Check
Weaknesses CWE-353
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-08-05T20:23:32.890Z

Reserved: 2026-07-27T15:53:40.951Z

Link: CVE-2026-17583

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T21:30:16Z

Weaknesses