Thermo Fisher Addresses Forensic DNA File Tampering Vulnerability in Software
Thermo Fisher addressed a critical vulnerability in DNA analysis tools by implementing digital signature verification to prevent unauthorized modifications to forensic data files.
Vulnerability Details
The flaw, which received a CVSS score of 8.2 out of 10 (CVSS 4.0), affects .fsa and .hid files generated by human-identification software. Researchers Nathan Adams, Kevin Dyer, Laura Gaydosh Combs, and the Cybersecurity and Infrastructure Security Agency (CISA) contributed to the discovery and coordinated disclosure of the vulnerability.
CVSS Score and Affected Files
Exploitation requires bypassing laboratory security measures to alter files after creation but before they are processed by analysis software. This could compromise the integrity of forensic results by introducing undetected changes to critical genetic data.
The Fix
Thermo Fisher released updates for five supported products to mitigate the risk. These patches introduce digital signatures that enable laboratories to confirm file authenticity, but the protection only applies to data generated after the updates are deployed.
Affected Software Versions
- 3500/3500xL Series Data Collection: Upgrade from version 4.0.2 or earlier to 4.0.3.
- 3730/3730xL Series Data Collection: Upgrade from version 5.0.2 or earlier to 5.0.3.
- SeqStudio Genetic Analyzer Data Collection: Upgrade from version 1.2.5 or earlier to 1.2.6.
- SeqStudio Flex Series Instrument: Upgrade from version 1.2.0 or earlier to 1.2.1.
- GeneMapper ID-X: Upgrade from version v1.7.3 or earlier to v1.7.4.
SAE Feature Requirements
For systems with Security, Audit, and E-signature (SAE) features enabled, users must first apply the latest SAE profile through the SAE Admin Console before installing the software update.
Older Platforms
Three older platforms will not receive patches as they have reached end-of-life status. These include:
- 3130 Series Data Collection version 4.1 or earlier.
- ABI PRISM 3100/3100-Avant Data Collection version 2.0 or earlier.
- ABI PRISM 310 Data Collection version 3.1 or earlier.
Recommendations
Thermo Fisher advised laboratories using unsupported software or unable to apply updates immediately to implement strict security protocols. Recommendations include maintaining a secure chain of custody for files, storing data on encrypted and password-protected storage devices, restricting access to authorized personnel, enforcing least-privilege permissions, and limiting network connectivity to trusted sources via firewalls and access controls.
“This could compromise the integrity of forensic results by introducing undetected changes to critical genetic data.”
