Junglewise Threat Intelligence

CVE-2024-35585: Oxford Nanopore MinKNOW IP-based authentication bypass

CVE-2024-35585 · Severity: high · CVSS 8.6 · Published 2026-09-02

Executive brief

MinKNOW is DNA and RNA sequencing software used in healthcare and research laboratories. A critical flaw allows remote attackers on the same network to bypass authentication by spoofing the IP address of an authorized client, gaining unauthorized access to sequencing operations. An attacker can pause data collection, steal sequencing results, or redirect output to an alternate location, disrupting laboratory workflows and compromising sensitive genetic data.

Technical details

CVE-2024-35585 is a missing authentication vulnerability (CWE-306) in MinKNOW versions before 24.06. The application relies solely on the client's source IP address for authentication rather than cryptographic credentials. Remote access is enabled by default, and an unauthenticated attacker on the same network can discover the sequencer via port scanning, register a temporary Oxford Nanopore account, and connect to the MinKNOW interface using a spoofed or matching IP address. The attack requires no authentication credentials, low attack complexity, and network reachability. Successful exploitation grants the attacker ability to observe, pause, or stop sequencing operations and redirect output data. Oxford Nanopore recommends upgrading to version 24.06 or later, keeping remote access disabled, and using only trusted networks.

Affected products

  • Oxford Nanopore Technologies MinKNOW before 24.06

Timeline

  • 2025-10-21: disclosed: CISA ICSMA-25-294-01 advisory published
  • 2024-06: patched: Version 24.06 patches CVE-2024-35585

References