Our takeCISA flags Thermo Fisher Applied Biosystems Genetic Analyzers: an attacker can modify .fsa/.hid DNA output files on Data Collection Software ≤4.0.2 (3500/3500xL) and 3730 series, producing inaccurate results. Labs running these should apply the vendor fix.Cyber Resilience desk
Sources (1)
- cisa_advisories · cisa_advisories
What this means for you — Security leader:Apply the CISA-issued patch for Applied Biosystems 3500/3500xL Data Collection Software <=4.0.2 and 3730/3730xl systems immediately; treat any .fsa or .hid files from unpatched instruments as potentially tampered.
What this means for you — Lean IT orgs:If your lab or clinic uses a Thermo Fisher Applied Biosystems 3500, 3500xL, 3730 or 3730xl Genetic Analyzer, check the Data Collection Software version and update it right away to protect DNA test results.
What this means for you — MSP:Audit client labs and diagnostic facilities for any Applied Biosystems 3500/3500xL (<=4.0.2) or 3730/3730xl instruments; deploy the vendor patch and validate output file integrity.
What this means for you — Researcher:Review and update any local or vendor-hosted Applied Biosystems 3500/3500xL (<=4.0.2) or 3730/3730xl Genetic Analyzer systems; assume .fsa/.hid files from unpatched units may have been altered.