Product Security Updates
MET ONE 3400+ Potential Credential Exposure (CVE-2025-0941)
February 18th, 2025
Beckman Coulter Life Sciences, through its vulnerability management processes, has identified a vulnerability in its MET ONE 3400+ Series instruments for which there is now a solution.
Specifically, under rare conditions, MET ONE 3400+ instruments running software version 1.0.41 may temporarily store credentials in plain text within a certain area of the system. Versions prior to 1.0.41 are not impacted. This data is not available to unauthenticated users.
Beckman Coulter Life Sciences has assessed this vulnerability as medium severity, with a score of 5.8 using the CVSS v3.1 specification.
The vulnerability has been fixed in software version 1.0.42. To upgrade to this software version, contact your authorized Beckman Coulter Field Service Representative.
Windows 10 IoT Enterprise LTSB 2015 Servicing Stack Update (CVE-2024-43491)
October 2nd, 2024
On September 10th, 2024, Microsoft published vulnerability notice CVE-2024-43491 which impacts computer systems running the Windows 10 Enterprise 2015 LTSB or Windows 10 IoT Enterprise 2015 LTSB operating systems. This vulnerability has a base CVSS v3.1 score of 9.8 Critical and has been added to the Known Exploited Vulnerabilities list by the United States Cybersecurity & Infrastructure Security Agency.
Beckman Coulter Life Sciences, through its vulnerability management processes, has identified the following products that are in scope of Microsoft’s notice CVE-2024-43491:
- i5 Automated Liquid Handler
- Biomek Automated Liquid Handler
- Biomek FXP Workstation
- Biomek NXP Automated
- Biomek 4000 Automated Liquid
This notice is only applicable to the above products using Windows 10 Enterprise 2015 LTSB or Windows 10 IoT Enterprise 2015 LTSB on their automation controller PCs. Users can check their Windows version by entering “winver” in the Run feature of the Start Menu of the PC.
Users of these devices are strongly advised to check that the automatic Windows Update feature of your automation controller PC is enabled as described in the Biomek Software Reference Manual (PN B56358). If automatic Windows updates have been disabled, users are strongly advised to apply the Windows patch KB5043083. Information for this patch can be found at the following site:
https://support.microsoft.com/en-us/topic/september-10-2024-kb5043083-os-build-10240- 20766-5a6c8182-b565-4b11-b127-97893b866ba1