CISA flags DNA tampering flaw and DICOM viewer crash bug

Two new federal advisories cover a high-severity flaw in Thermo Fisher DNA analyzers and a DICOM viewer bug that could allow code execution.

MedRisk Staff
By
2 Min Read

CISA issued two medical device advisories this week, flagging a high-severity flaw in Thermo Fisher genetic analyzers that could let attackers tamper with DNA data, and a DICOM viewer vulnerability that could crash or compromise radiology workstations.

The Thermo Fisher advisory, released August 4, covers CVE-2026-17583, a missing integrity check in Applied Biosystems Genetic Analyzer software rated CVSS 8.4. Because the instruments’ .fsa/.hid output files can be edited, an attacker could modify DNA data and produce inaccurate test results. The flaw affects the 3500, 3730, SeqStudio, and GeneMapper ID-X product lines, plus end-of-life 3130 and ABI PRISM systems. Patches are available for supported products; CISA recommends secure chain of custody, encrypted storage, and least-privilege access for laboratories that cannot update.

The second advisory, released August 6, covers CVE-2026-17264 in Medixant RadiAnt DICOM viewer versions up to 2025.2. Opening a crafted DICOM file with malicious JPEG-compressed pixel data triggers a heap out-of-bounds write that could allow remote code execution. The bug is rated CVSS 4.3, and version 2026.1 fixes it. CISA recommends opening DICOM files only from trusted sources.

Both product families are deployed worldwide in hospitals, diagnostic labs, and research settings. Genetic analyzers are central to clinical diagnostics, forensics, and biotech workflows, so tampered output could reach patient records before anyone notices. Radiology departments should inventory DICOM viewer versions and prioritize the Thermo Fisher patches, which carry the higher severity.

Share This Article