ZeroHour

CVE-2024-35585

niche

IP-address-based authentication bypass in Oxford Nanopore MinKNOW

CVSS 3.1
8.6 high
EPSS
<1%p21
Published
()
Modified
AI analysis

MinKNOW, Oxford Nanopore's software that controls and monitors its nanopore DNA/RNA sequencing devices, authenticates clients based only on the client's source IP address rather than a proper credential check (CWE-306). An attacker who can send requests from a source IP the host considers trusted, or who can make their traffic appear to come from such an IP (for example from within the same network path), is treated as an authenticated user without supplying credentials. Successful exploitation gives unauthenticated access to the sequencing control interface, which the CVSS score rates with high confidentiality impact and some integrity and availability impact, such as viewing or interfering with sequencing runs and data. Anyone running MinKNOW in a version before 24.06 is affected, most typically genomics research and clinical sequencing laboratories. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.

What to do: Upgrade MinKNOW to version 24.06 or later. Until then, restrict network access to MinKNOW's control interface so it is reachable only from explicitly trusted hosts or subnets, and check whether any MinKNOW instance is exposed beyond the local lab network, since IP-source authentication offers no protection against addresses that can be reached or spoofed within that scope.

Affected
Oxford Nanopore Technologies MinKNOWbefore 24.06
Estimated exposure
nicheorder of low tens of thousands of lab installations at most (specialized sequencer control software), with only a fraction network-exposed — MinKNOW runs only on Oxford Nanopore sequencers and their control hosts in research and clinical genomics labs, a small installed base that is typically reachable only on lab-internal networks rather than the internet, so the plausibly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.

Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

In the news

No ingested article mentions this CVE yet.