Affected Systems
Thermo Fisher Applied Biosystems human identification software: 3500/3500xL Series Data Collection ≤4.0.2, 3730/3730xL Series ≤5.0.2, SeqStudio Genetic Analyzer ≤1.2.5, SeqStudio Flex ≤1.2.0, GeneMapper ID-X ≤v1.7.3. Three EOL product lines (3130 Series, ABI PRISM 3100/3100-Avant, ABI PRISM 310) receive no patch. Affects .fsa and .hid DNA analysis data files used in forensic laboratories.
Exploitation Status
No known exploitation. Vendor confirmed to Wall Street Journal no instances of exploitation are known. Researchers demonstrated successful file modification in 45 minutes using publicly available AI tools. Requires local or remote access to laboratory servers and knowledge of DNA testing workflows. Not listed in CISA KEV catalog as of August 3, 2026.
Business Impact
Forensic laboratories using affected software face risk of undetectable tampering with DNA analysis files if laboratory access controls fail. Modified files raise no warnings in analysis software. Patches add digital signatures for future file validation but do not address retroactive validation of files generated before updates. Researchers indicate vulnerability may have existed in digital files since 1995, with no method to detect prior tampering. Physical DNA samples remain unaffected. High integrity risk for chain-of-custody in criminal justice and identification workflows.
Urgency
🟡 Within a week
Recommended Actions
- Install vendor patches immediately: 3500/3500xL Data Collection 4.0.3, 3730/3730xL 5.0.3, SeqStudio Genetic Analyzer 1.2.6, SeqStudio Flex 1.2.1 (with SAE profile update if SAE enabled), GeneMapper ID-X v1.7.4
- For EOL systems (3130, ABI PRISM 3100/3100-Avant, ABI PRISM 310), implement compensating controls: enforce strict file chain-of-custody, store files on encrypted password-protected media, apply least privilege on instrument and analysis systems
- Restrict network connectivity on forensic workstations and data collection systems to trusted sources only; isolate laboratory networks from general corporate infrastructure
- Review access logs for laboratory servers and file storage systems for unauthorized access or file modifications between initial data collection and analysis
- Establish file integrity monitoring on .fsa and .hid file repositories; document file hashes at time of generation for future validation where digital signatures are not yet in place
