CVE-2024-35585
nicheIP-address-based authentication bypass in Oxford Nanopore MinKNOW
MinKNOW, Oxford Nanopore's software that controls and monitors its nanopore DNA/RNA sequencing devices, authenticates clients based only on the client's source IP address rather than a proper credential check (CWE-306). An attacker who can send requests from a source IP the host considers trusted, or who can make their traffic appear to come from such an IP (for example from within the same network path), is treated as an authenticated user without supplying credentials. Successful exploitation gives unauthenticated access to the sequencing control interface, which the CVSS score rates with high confidentiality impact and some integrity and availability impact, such as viewing or interfering with sequencing runs and data. Anyone running MinKNOW in a version before 24.06 is affected, most typically genomics research and clinical sequencing laboratories. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.
What to do: Upgrade MinKNOW to version 24.06 or later. Until then, restrict network access to MinKNOW's control interface so it is reachable only from explicitly trusted hosts or subnets, and check whether any MinKNOW instance is exposed beyond the local lab network, since IP-source authentication offers no protection against addresses that can be reached or spoofed within that scope.
| Oxford Nanopore Technologies MinKNOW | before 24.06 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.
- Weakness
- CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.