# DNA Test Results Can Be Silently Falsified in Thermo Fisher Genetic Analyzers


## The Threat


The output files produced by Thermo Fisher Applied Biosystems genetic analyzers — the same instruments used in clinical diagnostics, forensic DNA analysis, and criminal justice proceedings — can be silently edited by anyone with access to the underlying file system. There is no integrity check. No signature. Nothing to alert a lab technician, a forensic examiner, or a court that the data has been touched.


CVE-2026-17583 documents what is, at its core, a trust problem baked into the software from the start. The .fsa and .hid output formats produced by these analyzers contain the raw electropherogram data that gets interpreted as a DNA profile. Strip out any verification mechanism for those files, and you've left a gap that an insider, a compromised workstation, or a sophisticated attacker could walk straight through. The tampered file looks identical to a legitimate one.


The scope is broad. The 3500, 3730, SeqStudio, GeneMapper ID-X, 3130, 3100, and 310 product lines are all affected — instruments that collectively represent years of installed base across hospital labs, medical examiner offices, and independent forensic laboratories worldwide. Several of those product lines are now end-of-life, meaning Thermo Fisher has issued no patch and won't be issuing one.


## Severity and Impact


| Field | Detail |

|---|---|

| CVE | CVE-2026-17583 |

| CVSS v3 Score | 8.4 (High) |

| CWE | CWE-353 — Missing Support for Integrity Check |

| Attack Complexity | Low |

| Authentication Required | Not specified (file-system level access) |

| Impact | Tampered DNA output data; inaccurate test results |

| Critical Sector | Healthcare and Public Health |

| Deployment | Worldwide |


## Affected Products


Patched versions available:

  • Applied Biosystems 3500/3500xL Series Data Collection Software ≤4.0.2 → update to 4.0.3
  • Applied Biosystems 3730/3730xL Series Data Collection Software ≤5.0.2 → update to 5.0.3
  • Applied Biosystems SeqStudio Genetic Analyzer Data Collection Software ≤1.2.5 → update to 1.2.6
  • Applied Biosystems SeqStudio Flex Series Instrument Software ≤1.2.0 → update to 1.2.1
  • Applied Biosystems GeneMapper ID-X Software ≤v1.7.3 → update to v1.7.4

  • End-of-Life — no patch will be issued:

  • Applied Biosystems 3130 Series Data Collection Software ≤4.1
  • ABI PRISM 3100/3100-Avant Data Collection Software ≤2.0
  • ABI PRISM 310 Data Collection Software ≤3.1

  • ## Mitigations


    Thermo Fisher's fix for supported products introduces digital signatures on instrument software, giving labs a mechanism to verify that output files have not been modified after generation. Update to the patched versions listed above as soon as your validation workflows allow.


    For labs that cannot immediately apply updates — or that are running end-of-life hardware — Thermo Fisher recommends the following interim controls:


  • Chain of custody: Maintain strict, documented chain of custody for all output files from the moment of generation
  • Access controls: Restrict file system access to analyzer workstations; apply least-privilege principles to any account that can reach the data directory
  • Network segmentation: Isolate analyzer workstations from broader network access where operationally feasible
  • Audit logging: Enable and review file access logs on workstations running affected software
  • Manual verification: Where possible, implement secondary review procedures for high-stakes results before they are used in clinical or legal decisions

  • Labs running EoL instruments face a harder choice: compensating controls can reduce risk, but they cannot close the gap that a vendor-issued integrity check would address. Organizations in that position should formally document the residual risk and evaluate accelerated hardware refresh timelines.


    ## References


  • [CISA ICS Advisory — Thermo Fisher Applied Biosystems Genetic Analyzers](https://www.cisa.gov/news-events/ics-advisories/)
  • [Thermo Fisher Scientific Security Advisories](https://www.thermofisher.com)
  • [NVD Entry: CVE-2026-17583](https://nvd.nist.gov/vuln/detail/CVE-2026-17583)

  • ---


    ## HackWire Analysis


    The cybersecurity community tends to get exercised about hospital networks and ransomware — understandably so. But the deeper, quieter risk in healthcare IT is the category of vulnerabilities that don't crash systems. They corrupt data. And corrupted DNA data is a particularly consequential category of corrupted data.


    Forensic genetics already lives inside a contested evidentiary space. Defense attorneys routinely challenge DNA match probabilities, lab procedures, and chain-of-custody documentation. CVE-2026-17583 hands anyone motivated to challenge — or manufacture — DNA evidence a technical lever that previously required either physical access to evidence or sophisticated laboratory fraud. Now it requires file system access and a hex editor.


    The EoL situation deserves direct attention. Three of the eight affected product lines are receiving no patch. The 3130 series, the 3100/3100-Avant, and the 310 are all still in use across clinical and forensic settings, particularly in resource-constrained labs and developing-country contexts where hardware refresh cycles stretch for a decade or more. Thermo Fisher's compensating controls guidance is reasonable, but "maintain chain of custody" was already a requirement — it didn't prevent this gap from existing in the first place.


    What's changed with this disclosure is that the gap is now public. Labs that processed high-stakes cases on unpatched analyzers should consider whether results in pending legal proceedings warrant secondary validation. That's an uncomfortable recommendation, but it's the honest one.


    Defenders should treat this as an insider-threat scenario first: the most plausible exploitation path runs through a disgruntled employee or a compromised workstation on the lab network, not a remote attacker. Access controls and audit logging are the short-term answer. Patching is the only real fix.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)