highOther

Thermo Fisher Applied Biosystems Genetic Analyzers - Missing Integrity Check on .fsa/.hid Files (CVE-2026-17583)

First seen Aug 5, 2026 · Updated Aug 5, 2026 · CVSS 8.4

ICSmedical-devicedata-integrityhealthcareCWE-353CVSS-8.4local-attack-vectorforensic-data-tampering

A vulnerability in multiple Thermo Fisher Applied Biosystems Genetic Analyzer software products allows tampering with .fsa/.hid output files due to missing integrity checks, which could result in falsified DNA test results. The flaw requires local access and no user interaction, affecting eight product lines including several that are end-of-life with no patch available.

Technical Analysis

CVE-2026-17583 (CVSS 3.1: 8.4, CVSS 4.0: 8.2) stems from CWE-353 (Missing Support for Integrity Check), enabling a local attacker to modify .fsa/.hid genetic analysis output files without detection, compromising the integrity and confidentiality of DNA test data used in forensic, clinical, and research workflows. The attack vector is local (AV:L) with no privileges or user interaction required, meaning an attacker with access to the host system or shared storage could silently alter genetic test outcomes. Thermo Fisher has released patches for several product lines (3500/3500xL, 3730/3730xL, SeqStudio, SeqStudio Flex, GeneMapper ID-X) that add digital signature verification, but three product lines (3130 Series, ABI PRISM 3100/3100-Avant, ABI PRISM 310) are end-of-life and will not receive fixes. This vulnerability has no direct AI agent system impact, as it affects specialized laboratory instrumentation software and forensic data files rather than infrastructure, credentials, or software components typically used by AI agents or LLM tool-use pipelines.

Affected Systems

Applied Biosystems 3500/3500xL Series Data Collection Software <=4.0.2; Applied Biosystems 3730/3730xL Series Data Collection Software <=5.0.2; Applied Biosystems SeqStudio Genetic Analyzer Data Collection Software <=1.2.5; Applied Biosystems SeqStudio Flex Series Instrument Software <=1.2.0; Applied Biosystems GeneMapper ID-X Software <=1.7.3; Applied Biosystems 3130 Series Data Collection Software <=4.1 (EoL); ABI PRISM 3100/3100-Avant Data Collection Software <=2.0 (EoL); ABI PRISM 310 Data Collection Software <=3.1 (EoL)

Indicators of Compromise

  • No known IOCs - this is a design/architecture vulnerability, not an active exploit campaign
  • Affected file types: .fsa, .hid

Remediation Steps

  1. 1

    Apply vendor patches

    Update to patched versions: 3500/3500xL DCS v4.0.3, 3730/3730xL UDC v5.0.3, SeqStudio v1.2.6, SeqStudio Flex v1.2.1, GeneMapper ID-X v1.7.4. These add digital signature support to verify data file integrity.

  2. 2

    Address end-of-life systems

    For 3130 Series, ABI PRISM 3100/3100-Avant, and ABI PRISM 310 (no vendor fix available), plan migration to supported hardware/software or implement compensating controls.

  3. 3

    Maintain chain of custody

    Establish and enforce a secure chain of custody for all files generated by HID instrumentation throughout the analysis workflow.

  4. 4

    Encrypt and restrict storage

    Store generated .fsa/.hid files on encrypted, password-protected storage media and restrict access to authorized personnel only, per laboratory access control policies.

  5. 5

    Apply least privilege and network restrictions

    Limit user permissions on systems running HID instrumentation or analysis software, and use firewall rules/NACLs to restrict network and internet connectivity to trusted sources only. Ensure control system devices are not accessible from the internet.

CVE / Advisory IDs

CVE-2026-17583

Industries Most Exposed

HealthcareForensicsLife SciencesPublic HealthResearch

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.