Thermo Fisher Scientific has addressed a vulnerability in certain Applied Biosystems human identification software, enabling potential alterations to data files prior to analysis software loading them This article explores laboratory safeguards bypassed. . The company's July 31 security update indicates that subtle changes might be introduced into .fsa and .hid outputs if laboratory safeguards are bypassed.
Thermo Fisher is tracking this issue under the entity "ENTITY_0" and has assigned it a high rating with a CVSS score of 8.2. If your laboratory uses SeqStudio Flex and requires security, audit, and electronic signature (SAE) features enabled, you must install the latest SAE profile on the SAE Admin Console first.
Three older lines are off the radar: 3130 Series Data Collection Software 4.1 and earlier versions, ABI PRISM 3100/3100-Avant Data Collection Software 2.0 and lower, and ABI PRISM 310 Data Collection Software 3.1 and below. The company recommends customers who cannot implement the necessary updates or switch to another third-party analysis platform take the following steps: maintain a chain of custody, store files on encrypted and password-protected media, restrict access, apply least privilege on instrument and analysis systems, and limit internet connectivity to trusted sources. The researchers informed the Journal that the vulnerability likely existed in digital files produced by crime-lab machines since 1995 and they have not found a method to detect prior tampering if it occurred.












