Full Report
Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them. The vendor's July 31 security bulletin says nearly undetectable changes to .fsa and .hid outputs could occur if laboratory controls are circumvented. Thermo Fisher tracks the issue as CVE-2026-17583 and rates it
Analysis Summary
# Vulnerability: DNA Data File Tampering in Thermo Fisher Applied Biosystems Software
## CVE Details
- **CVE ID:** CVE-2026-17583
- **CVSS Score:** 8.2 (High) via CVSS v4.0
- **CWE:** Not specified (Related to lack of data integrity validation/digital signatures)
## Affected Systems
- **Products:** Applied Biosystems Human Identification (HID) and Data Collection Software.
- **Versions:**
- 3500/3500xL Series Data Collection Software: v4.0.2 and earlier
- 3730/3730xL Series Data Collection Software: v5.0.2 and earlier
- SeqStudio Genetic Analyzer Data Collection Software: v1.2.5 and earlier
- SeqStudio Flex Series Instrument Software: v1.2.0 and earlier
- GeneMapper ID-X Software: v1.7.3 and earlier
- **End-of-Life (No Patch):** 3130 Series, ABI PRISM 3100/3100-Avant, and ABI PRISM 310 Data Collection Software.
## Vulnerability Description
The flaw allows for the nearly undetectable modification of `.fsa` and `.hid` output files—standard formats for DNA profile data—before they are loaded into analysis software. Historically, these files lacked digital signatures, allowing an attacker to manipulate DNA scan data to create fraudulent profiles (e.g., combining scans from two different individuals). Analysis software would then process these altered files without triggering warnings, potentially compromising 30 years of forensic evidence integrity.
## Exploitation
- **Status:** Not known to be exploited in the wild.
- **Complexity:** Medium (Requires knowledge of DNA testing/forensics; researchers successfully used AI/Claude to assist in file modification within 45 minutes).
- **Attack Vector:** Local or Remote (Requires access to a laboratory’s servers or instrument systems).
## Impact
- **Confidentiality:** Low/None (Primary focus is on data alteration).
- **Integrity:** High (Files can be modified to change DNA results without detection).
- **Availability:** Low.
## Remediation
### Patches
Thermo Fisher has released updates that implement digital signatures to verify file integrity:
- **3500/3500xL:** Update to v4.0.3
- **3730/3730xL:** Update to v5.0.3
- **SeqStudio:** Update to v1.2.6
- **SeqStudio Flex:** Update to v1.2.1 (Requires updating the SAE Admin Console profile)
- **GeneMapper ID-X:** Update to v1.7.4
### Workarounds
For EOL systems or those unable to patch:
- Maintain strict physical and digital chain of custody.
- Store files on encrypted, password-protected media.
- Apply the principle of least privilege to instrument and analysis accounts.
- Isolate systems from the internet or limit connectivity to trusted sources.
## Detection
- **Indicators of Compromise:** There are currently no methods to detect prior tampering of historical files generated before digital signatures were implemented.
- **Detection Methods:** For updated systems, the software will now use digital signatures to flag files that have been modified after generation.
## References
- **Vendor Advisory:** hxxps://documents.thermofisher[.]com/TFS-Assets/CORP/Product-Guides/fsa_hid_bulletin.pdf
- **News Source:** hxxps://thehackernews[.]com/2026/08/thermo-fisher-patches-flaw-that-could.html
- **Related Coverage:** hxxps://www.wsj[.]com/tech/cybersecurity/security-flaw-placed-30-years-of-dna-evidence-at-risk-of-hacking-1932775a