CVE-2024-35585: High severity Oxford Nanopore Technologies MinKNOW vulnerability
Published Sep 2, 2026
·Updated
Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.
Affected Software
1 affected component
Oxford Nanopore Technologies MinKNOW<24.06
Event History
Sep 2, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker who can reach the affected MinKNOW service over the network may be able to exploit it without privileges or user interaction, because authentication relies on the client source IP address.
2
Which deployments are affected?
Oxford Nanopore Technologies MinKNOW versions before 24.06 are affected. The provided information does not identify any configuration requirement or exception.
3
What is the potential impact?
The reported severity vector indicates high confidentiality impact and low integrity and availability impact. Exploitation is rated network-accessible, low complexity, and requires neither privileges nor user interaction.