PT-2026-84597 · Oxford Nanopore · Minknow
CVE-2024-35585
·
Published
2026-09-02
·
Updated
2026-09-02
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Oxford Nanopore MinKNOW versions prior to 24.06
Description
The software relies on the client's source IP address for authentication, which can be bypassed or spoofed to gain unauthorized access.
Recommendations
Update to version 24.06 or later.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Minknow