Vulnerabilities

Critical Security Vulnerability found in Illumina iSeq 100 DNA Sequencers

0

Security researchers have uncovered significant vulnerabilities in the BIOS/UEFI firmware of the iSeq 100 DNA sequencer, a product developed by U.S. biotechnology company Illumina. These flaws could allow attackers to disable the device or implant persistent malware, potentially disrupting its vital role in illness detection and vaccine development.

The Illumina iSeq 100 is promoted as a cost-effective and rapid DNA sequencing system for medical and research laboratories. However, a recent analysis by firmware security firm Eclypsium revealed severe security gaps in its BIOS firmware. The device lacked standard write protections, making it susceptible to malicious code modifications that could “brick” the system or embed long-term threats.

Outdated and Vulnerable BIOS

Eclypsium’s researchers discovered that the iSeq 100 was running an outdated BIOS version (B480AM12, dated April 12, 2018) in Compatibility Support Mode (CSM), a legacy feature for supporting older hardware. This configuration not only bypasses modern protections like Secure Boot but also leaves the system exposed to various attacks, including:

  • LogoFAIL
  • Spectre 2
  • Microarchitectural Data Sampling (MDS)

The absence of Secure Boot, which ensures the integrity of boot code, compounded the risk. Attackers could exploit these vulnerabilities to tamper with firmware, disable the device, or alter test results, with potentially devastating consequences.

The iSeq 100 relies on an OEM motherboard supplied by IEI Integration Corp, a company that produces a wide range of industrial and medical computer products. Eclypsium warns that similar vulnerabilities might exist in other devices using IEI motherboards, posing broader risks to the medical and industrial sectors.

The report underscores the appeal of DNA sequencing systems to various threat actors. Financially motivated attackers, such as ransomware groups, could target these systems to disrupt operations and demand ransoms. State-sponsored actors might also exploit these vulnerabilities, given the critical role of DNA sequencers in detecting genetic illnesses, cancer, drug-resistant bacteria, and developing vaccines.

Response and Mitigation

Illumina was notified of the issues and has since issued a patch to affected customers. The company made a statement that their initial evaluation indicates these issues are not high-risk. The company is committed to the security of the products and the privacy of genomic data. They also added that it would notify impacted customers and provide necessary mitigations as part of its standard processes.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Moxa issues alert on High-Severity Router Vulnerabilities

Previous article

UK Domain Registry Nominet hit by Ivanti Zero-Day Exploit

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *