CVE-2026-17583 Details
Description
The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes.
A vulnerability exists in certain Thermo Fisher Applied Biosystems Genetic Analyzers due to the lack of integrity checks on .fsa and .hid output files. This flaw allows for nearly undetectable modifications to these files, potentially altering DNA data and leading to inaccurate test results. The affected software versions include: 3500/3500xL Series Data Collection Software (through 4.0.2), 3730/3730xL Series Data Collection Software (through 5.0.2), SeqStudio Genetic Analyzer Data Collection Software (through 1.2.5), SeqStudio Flex Series Instrument Software (through 1.2.0), GeneMapper ID-X Software (through 1.7.3), 3130 Series Data Collection Software (through 4.1), and ABI PRISM 3100/3100-Avant Data Collection Software (through 2.0)
Users are advised to update to the latest versions of the affected software. For those using the SeqStudio Flex system with SAE enabled, the latest SAE profile must be installed before applying the update.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://documents.thermofisher.com/TFS-Assets/CORP/Product-Guides/fsa_hid_bulletin.pdf | [email protected] | PatchVendor Advisory |
| https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-216-01 | [email protected] | PatchThird Party AdvisoryUS Government Resource |
| https://www.cve.org/CVERecord?id=CVE-2026-17583 | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-353 | Missing Support for Integrity Check | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| thermofisher abi prism 310 data collection software | <= 3.1 |
CPE
Remediation
| |
| thermofisher abi prism 3100/3100-avant data collection software | <= 2.0 |
CPE
Remediation
| |
| thermofisher applied biosystems 3130 series data collection software | <= 4.1 |
CPE
Remediation
| |
| thermofisher applied biosystems 3500/3500xl series data collection software | < 4.0.3 |
CPE
Remediation
| |
| thermofisher applied biosystems 3730/3730xl series data collection software | < 5.0.3 |
CPE
Remediation
| |
| thermofisher applied biosystems seqstudio flex series instrument software | < 1.2.1 |
CPE
Remediation
| |
| thermofisher applied biosystems seqstudio genetic analyzer data collection software | < 1.2.6 |
CPE
Remediation
| |
| thermofisher genemapper id-x | < 1.7.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 26, 2026 | Reanalysis | [email protected] |
| Aug 26, 2026 | Initial Analysis | [email protected] |
| Aug 6, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | New CVE Received | [email protected] |