Illumina Local Run Manager privilege escalation | CVE-2022-1517
NAME
Illumina Local Run Manager privilege escalation
- Platforms Affected:
Illumina Local Run Manager 3.1
Illumina Local Run Manager 1.3 - Risk Level:
10 - Exploitability:
Unproven - Consequences:
Gain Privileges
DESCRIPTION
Illumina Local Run Manager could allow a remote attacker to gain elevated privileges on the system, caused by execution with unnecessary privileges. By sending a specially-crafted request, an attacker could exploit this vulnerability to change settings, configurations, and software on the affected device, obtain sensitive information, or access APIs that are not intended for general use.
CVSS 3.0 Information
- Privileges Required: None
- User Interaction: None
- Scope: Changed
- Access Vector: Network
- Access Complexity: Low
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
- Remediation Level: Official Fix
MITIGATION
Apply the patch for this vulnerability (Local Run Manager Software Patch 1.0), available from the Illumina Web site. See References.
- Reference Link:
https://www.cisa.gov/uscert/ics/advisories/icsa-22-153-02 - Reference Link:
https://support.illumina.com/downloads/local-run-manager-sw-patch-instruction-guide.html
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.