MinKNOW is the control software for Oxford Nanopore DNA and RNA sequencers. ICSMA-25-294-01 says versions before 24.06 and 24.11 shipped with CVE-2024-35585, missing authentication for a critical function, base score 8.6. Two more come with it: insufficiently protected credentials at 7.8, and an improper check for exceptional conditions. Together they let an attacker disrupt sequencing runs, exfiltrate or alter data, and bypass authentication.
Missing authentication for a critical function is the absence of a check that should exist. An operation the software treats as sensitive can be invoked by anyone able to reach the interface, because the code never stops to ask who is calling. On a control plane the omission is total, since there is no weak password to guess when no prompt appears at all.
A University of Florida team, Sara Rampazzi, Christina Boucher, Carson Stillman and Jonathan Bravo, reported it. Sequencers are drifting from the research bench into clinical and public-health workflows, which changes what a manipulated result costs.
When a sequencer moves into clinical or public-health use, its output stops being a data point in a study and becomes the basis for a diagnosis or a surveillance decision. An adversary who can quietly alter a result, rather than merely halt a run, corrupts the conclusion drawn from it, and the corruption may never announce itself. Availability matters too, since a run stopped midway can waste scarce reagents and irreplaceable samples.
The finding also reflects who is now looking. Academic security teams have begun turning the scrutiny once reserved for hospital devices onto laboratory instruments. Equipment designed for a trusted lab, where physical presence was the only real gatekeeper, carries assumptions that collapse once it answers to remote requests.
Update MinKNOW. And note the pattern: research-grade instruments were built when the threat model was a curious grad student, not a network adversary. That assumption expires the moment the box gets an IP address.