Vulnerability in Thermo Fisher Genetic Analyzers Allows File Tampering
CVE-2026-17583

8.3HIGH

What is CVE-2026-17583?

CVE-2026-17583 is a serious vulnerability affecting the Thermo Fisher Applied Biosystems Genetic Analyzers. These devices are used primarily for DNA analysis and genetic testing, which are crucial in various fields such as healthcare, forensic science, and biological research. The vulnerability arises from the ability to tamper with .fsa/.hid output files generated by the analyzers. Attackers could exploit this flaw to modify these files, potentially altering critical DNA data and leading to inaccurate test results. Such manipulation could have dire consequences, including misdiagnoses, wrongful legal conclusions, or misguided research results, ultimately jeopardizing patient safety and trust in genetic testing processes.

Potential impact of CVE-2026-17583

  1. Inaccurate Test Results: The primary concern with this vulnerability is the risk of generating incorrect DNA analysis outcomes. This can lead to false positives or negatives in genetic testing, adversely affecting clinical decisions and patient health.

  2. Legal and Ethical Implications: Tampering with genetic data can have severe legal ramifications. Misleading results could result in wrongful legal actions, particularly in forensic cases or paternity tests, where accurate DNA analysis is critical.

  3. Loss of Trust and Reputational Damage: Organizations relying on accurate genetic testing may face a significant erosion of trust from patients, professionals, and regulatory bodies. This concern can lead to reputational harm and possible regulatory scrutiny, impacting business operations and stakeholder relationships.

Affected Version(s)

ABI PRISM 310 Data Collection Software 0 <= 3.1

ABI PRISM 3100/3100-Avant Data Collection Software 0 <= 2.0

Applied Biosystems 3130 Series Data Collection Software 0 <= 4.1

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Thermo Fisher Patches Forensic DNA File Tampering Flaw in Its Software

Thermo Fisher patched CVE-2026-17583 in five supported DNA analysis products by adding digital signatures that help laboratories detect modified forensic files.

2 days ago

Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable

Thermo Fisher patched CVE-2026-17583, which could let attackers make nearly undetectable changes to Applied Biosystems DNA files before analysis.

3 days ago

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • πŸ“°

    First article discovered by The Hacker News

  • Vulnerability Reserved

Credit

Nathaniel Adams, Laura Gaydosh-Combs, and Kevin Dyer reported this vulnerability to CISA.
.