CVE-2024-35585 Details
Description
Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.
A vulnerability exists in Oxford Nanopore MinKNOW versions prior to 24.06, where authentication relies on the client's source IP address. This flaw allows unauthorized users on the same network to access the sequencer by registering a legitimate or temporary Oxford Nanopore account. Once connected through the MinKNOW application, these users can observe sequencing activity, pause or stop data collection, and redirect output data to another location. Additionally, the software stores authentication tokens in a temporary directory that is typically world-readable, creating another avenue for unauthorized access if the token is leaked.
Users are advised to upgrade to MinKNOW versions later than 24.11. For those on version 24.06 who cannot upgrade immediately, Oxford Nanopore recommends keeping Remote Connect disabled unless strictly necessary, and maintaining antivirus and malware scanning tools. Users should contact Oxford Nanopore Support for guidance on securing their configurations if they are unable to upgrade.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 2, 2026CISA-ADP
Assessed Sep 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-294-01 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Oxford Nanopore MinKNOW | < 24.06 < 24.11 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 2, 2026 | CVE Modified | CISA-ADP |
| Sep 2, 2026 | New CVE Received | [email protected] |
Volerion