Thermo Fisher Applied Biosystems Genetic Analyzers
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to modify .fsa/.hid output files, tampering with DNA data and resulting in inaccurate test results. The following versions of Thermo Fisher Applied Biosystems Genetic Analyzers are affected: Applied Biosystems 3500/3500xL Series Data Collection Software <=4.0.2 Applied Biosystems 3730/3730xL Series Data Collection Software <=5.0.2 Applied Biosystems SeqStudio Genetic Analyzer Data Collection Software <=1.2.5 Applied Biosystems SeqStudio Flex Series Instrument Software <=1.2.0 Applied Biosystems GeneMapper ID-X Software <=v1.7.3 Applied Biosystems 3130 Series Data Collection Software <=4.1 ABI PRISM 3100/3100-Avant Data Collection Software <=2.0 ABI PRISM 310 Data Collection Software <=3.1 CVSS Vendor Equipment Vulnerabilities v3 8.4 Thermo Fisher Thermo Fisher Applied Biosystems Genetic Analyzers Missing Support for Integrity Check Background Critical Infrastructure Sectors: Healthcare and Public Health Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-17583 The affected product is vulnerable because its .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes. View CVE Details Affected Products Thermo Fisher Applied Biosystems Genetic Analyzers Vendor: Thermo Fisher Product Version: Thermo Fisher Applied Biosystems 3500/3500xL Series Data Collection Software: <=4.0.2, Thermo Fisher Applied Biosystems 3730/3730xL Series Data Collection Software: <=5.0.2, Thermo Fisher Applied Biosystems SeqStudio Genetic Analyzer Data Collection Software: <=1.2.5, Thermo Fisher Applied Biosystems SeqStudio Flex Series Instrument Software: <=1.2.0, Thermo Fisher Applied Biosystems GeneMapper ID-X Software: <=v1.7.3, Thermo Fisher Applied Biosystems 3130 Series Data Collection Software: <=4.1, Thermo Fisher ABI PRISM 3100/3100-Avant Data Collec
CSIRTS triage
- What
- Improper link resolution before file access vulnerability in Dell Display and Peripheral Manager for macOS.
- Who is affected
- macOS deployments of DDPM prior to version 2.3.0.1005.
- Urgency
- Patch as link-following vulnerabilities can lead to unauthorized file access and information disclosure.
- Action
- Update DDPM Mac to version 2.3.0.1005 or later.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Display and Peripheral Manager (DDPM Mac)
Get an email when a new Display and Peripheral Manager (DDPM Mac) advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-216-01
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-175830.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-17583 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Thermo Fisher Applied
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
More from CISA Cybersecurity Advisories
- highCISA Adds Three Known Exploited Vulnerabilities to Catalog2026-09-11
- highCISA Adds One Known Exploited Vulnerability to Catalog2026-09-11
- criticalAVEVA Pipeline Integrity Monitor2026-09-10
- criticalNextGen Healthcare Mirth Connect2026-09-10
- criticalOrthanc DICOM Server2026-09-10