Correction — Thermo Fisher shipped patched software for CVE-2026-17583 on five genetic-analyzer product lines, and the update implements exactly the file-integrity control this pipeline said did not exist
UPDATE · originally covered CVE-2026-17583 — Thermo Fisher Applied Biosystems genetic analyzers write DNA result files with no integrity checking, so results can be altered after the run and no vendor fix is offered (2026-08-05)
the earlier entry's central claim was false, and the correction runs the wrong way round from the usual — a flaw this pipeline described as unfixable has a fix, and readers were told not to look for one.
CISA's advisory ICSMA-26-216-01 carries eight per-product vendor-fix records for this flaw, alongside seven mitigation records. Five of the eight name a patched version for a specific product line: "Applied Biosystems 3500/3500xL Series Data Collection Software: Update to version 4.0.3", and correspondingly 3730/3730xL Data Collection Software to 5.0.3, SeqStudio Genetic Analyzer Data Collection Software to 1.2.6, SeqStudio Flex Series Instrument Software to 1.2.1, and GeneMapper ID-X Software to 1.7.4 (CISA ICSMA-26-216-01 (CSAF), 2026-08-04). Three products are genuinely unfixed, and the advisory says why rather than staying silent: the 3130 Series, ABI PRISM 3100/3100-Avant and ABI PRISM 310 Data Collection Software each carry "Product is End of Life (EoL), no update provided" (CISA ICSMA-26-216-01 (CSAF), 2026-08-04). The original entry generalised the end-of-life products' position to the whole product set.
The substance of the fix matters as much as its existence, because the earlier entry argued that no software update could address the problem and that only an architectural control — moving completed .fsa/.hid files into append-only or signed storage — would do. The advisory says the updates do precisely that job in the instrument software: "Thermo Fisher has developed security updates to address the vulnerability. The security updates implement the use of digital signatures on the instrument software that adds an extralayer of protection. Moving forward, this will help users verify that data files have not been modified" (CISA ICSMA-26-216-01 (CSAF), 2026-08-04). The interim measures the original entry treated as the whole answer — encrypted storage media, access restriction to authorised personnel, least privilege on the instrument hosts, and firewall rules and network ACLs limiting internet connectivity to trusted sources — are in the advisory as what to do until the applicable updates are installed, not instead of them.
Nothing about the flaw itself changes: the CVSS 3.1 base score of 8.4, the local attack vector, the affected version list and the mechanism — result files written with no integrity checking, so a file altered after the run reads as authentic — were all correct in the original entry and were re-verified in this audit. What changes is the disposition. For five of the eight product lines this is a patching task on a normal change window, and the frontmatter here supersedes the earlier status: [no-patch] and its empty fixed field, both of which would otherwise leave an automated triage consumer answering "is my version patched?" with a wrong no.
Triage: an instrument host still reporting a Data Collection Software version at or below the affected boundary after the update window is the discriminator between "unpatchable end-of-life product" and "patchable product nobody updated" — the two look identical in an asset inventory that records only the product family, and only the version string separates them.
Thermo Fisher has developed security updates to address the vulnerability. The security updates implement the use of digital signatures on the instrument software that adds an extralayer of protection. Moving forward, this will help users verify that data files have not been modified.
Applied Biosystems 3500/3500xL Series Data Collection Software: Update to version 4.0.3
Applied Biosystems 3130 Series Data Collection Software: Product is End of Life (EoL), no update provided
Defender actions
- Update the genetic-analyzer software this entry names to 4.0.3, 5.0.3, 1.2.6, 1.2.1 or 1.7.4 as applicable, rather than treating the flaw as unpatchable — and for the three end-of-life ABI PRISM and 3130 Series lines, where no update exists, keep the archival control the earlier entry described, because for those products it remains the only option.
ATT&CK mapping
1 technique mapped from the cited reporting · MITRE ATT&CK v19.2
Impact TA0040
T1565.001Data Manipulation: Stored Data Manipulation
Adversaries may insert, delete, or manipulate data at rest in order to influence external outcomes or hide activity, thus threatening the integrity of the data. By manipulating stored data, adversaries may attempt to affect a business process, organizational understanding, and decision making.
Sources
Update chain
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.