Executive brief
The Eppendorf BioFlo 320, a bioreactor used in laboratory and bioprocessing environments, contains a security flaw where its remote access interface uses a permanent, unchangeable password. If an attacker identifies the device on a network, they can use this password to take full control of the bioreactor's control panel. This could allow unauthorized individuals to alter critical research parameters, disrupt operations, or access sensitive process data.
Technical details
The vulnerability (CWE-259) exists because the Virtual Network Computing (VNC) server on the Eppendorf BioFlo 320 uses a hard-coded password. An attacker with network connectivity to the device can authenticate via VNC without knowing a unique user-defined credential, gaining full access to the control panel. Additionally, VNC traffic on this device is unencrypted, exposing session data to interception. While VNC is disabled by default and must be enabled locally, once active, it provides a high-impact vector for remote command and control. Eppendorf has released software version 5.0 which mitigates the issue by permanently removing VNC access from the controller.
Affected products
- Eppendorf BioFlo 320 Bioreactor All versions prior to software version 5.0
Timeline
- 2026-05-26: advisory: CISA and Eppendorf released security advisories.
- 2026-05-26: patched: Software version 5.0 released to remove the vulnerable VNC component.