Thermo Fisher Scientific has released security updates for Applied Biosystems software to prevent unauthorized tampering with DNA data files that could potentially compromise forensic analysis and laboratory integrity.
Key Points
- Thermo Fisher issued patches for five product lines to add digital signatures, preventing undetectable modifications to .fsa and .hid DNA data files.
- The vulnerability, tracked as CVE-2026-17583, received a high CVSS v4.0 score of 8.2 due to the risk of data manipulation before analysis.
- Three legacy product lines, including the 3130 and 3100 series, have reached end-of-life status and will not receive security updates.
- Researchers demonstrated that modified DNA files could bypass existing detection software, potentially allowing the creation of fraudulent profiles from existing data.
- The company recommends that laboratories unable to update their software implement strict access controls, file encryption, and network restrictions to maintain data integrity.