Thermo Fisher: High-Severity Flaw Could Alter Genetic Data in Applied Biosystems Systems
A high-severity flaw CVE-2026-17583 in Thermo Fisher's Applied Biosystems software could alter genetic data. Learn about affected versions and fixes.
Illustrative image generated with AI
CVE-2026-17583 Affects the Integrity of Genetic Files
Thermo Fisher Scientific has disclosed a vulnerability in the integrity checks applied to .fsa and .hid files produced or handled by several Applied Biosystems software products. Tracked as CVE-2026-17583, the flaw was identified on August 4, 2026.
An attacker with local access to the system or to storage media containing the files could modify their contents without the software necessarily detecting the tampering. The resulting data might therefore no longer match the genetic material analyzed.
The vulnerability is rated high severity, with a score of 8.4 under CVSS 3.1 and 8.2 under CVSS 4.0. It is associated with CWE-353, which concerns the lack of adequate mechanisms for verifying data integrity.
Affected Software and Potential Impact
The following versions are vulnerable:
- Applied Biosystems 3500/3500xL Data Collection Software
<=4.0.2 - Applied Biosystems 3730/3730xL Data Collection Software
<=5.0.2 - SeqStudio Genetic Analyzer Data Collection Software
<=1.2.5 - SeqStudio Flex Instrument Software
<=1.2.0 - GeneMapper ID-X Software
<=1.7.3 - Applied Biosystems 3130 Series Data Collection Software
<=4.1 - ABI PRISM 3100/3100-Avant Data Collection Software
<=2.0 - ABI PRISM 310 Data Collection Software
<=3.1
These products are used worldwide in healthcare, public health, and forensic applications. File tampering could falsify DNA profiles or generate inaccurate results during clinical analyses, genetic identification, and criminal investigations.
The CVSS attack vector requires local access but no prior privileges or user interaction. A successful compromise could affect the confidentiality, integrity, and availability of the data.
Available Updates and Temporary Mitigations
Thermo Fisher has released updated versions that verify files using digital signatures:
- 3500/3500xL: version
4.0.3 - 3730/3730xL: version
5.0.3 - SeqStudio: version
1.2.6 - SeqStudio Flex: version
1.2.1 - GeneMapper ID-X: version
1.7.4
The 3130, ABI PRISM 3100/3100-Avant, and ABI PRISM 310 product lines are End of Life and will not receive fixes. Organizations using these systems should consider compensating controls or platform replacement.
Before applying updates, organizations should maintain a verifiable chain of custody for files, use encrypted and password-protected storage media, and restrict access to authorized personnel. Least-privilege principles are also recommended, along with reduced connectivity through firewalls and network ACLs.
Sources
This article is an original reworking based on the sources below.




