FDA, CISA warn of vulnerabilities in medical devices used for genetic testing
Summary
FDA, CISA warn of vulnerabilities in medical devices used for genetic testing The U.S. Food and Drug Administration (FDA) and Cybersecurity and Infrastructure Security Agency (CISA) warned on Thursday that vulnerabilities have been found in software from Illumina, a company that produces tools used for genetic analysis. The vulnerabilities affect software in medical devices used for clinical diagnostic use in sequencing a person’s DNA, testing for various genetic conditions, or for research purposes. The FDA urged users to either install the patches or contact the company for assistance if an instrument is not connected to the internet. The most concerning vulnerability – CVE-2022-1517 – has a CVSS score of 10 and allows an attacker to upload and execute code remotely at the operating system level. There are also several other vulnerabilities cited in the CISA notice, including CVE-2022-1518, which also has a CVSS score of 10 and allows attackers to upload outside the intended directory structure.