Impact
A flaw in NASA’s CubeSat Operating System, cFS, causes an out‑of‑bounds read inside the CFE_FS_ParseInputFileNameEx function. The reading of memory outside the intended buffer is tied to CWE‑119 (Improper Restriction of Operations within the Bounds of a Buffer) and CWE‑125 (Out‑of‑Bounds Read). If an attacker can supply a crafted file name, the function may read unintended memory contents, potentially leading to information disclosure or further exploitation. The description states that remote exploitation of the attack is possible, making this a significant risk for systems that expose this API to adversaries.
Affected Systems
NASA cFS systems running versions up to and including 7.0.1 are affected. The vulnerability resides in the cfe/modules/fs/fsw/src/cfe_fs_api.c file of the cFS product. All installations that have not applied the pending pull request to address this issue remain vulnerable.
Risk and Exploitability
The CVSS score of 5.1 reflects a moderate severity, but the EPSS is currently not available, making it unclear how frequently an attacker would discover or target this flaw. The vulnerability is not listed in the CISA KEV catalog, suggesting no evidence of real‑world exploit yet. Nevertheless, the description confirms that remote exploitation is possible, meaning an attacker who can interact with the cFS instance may trigger the out‑of‑bounds read. Without an official patch, systems are at risk until a corrected build is released.
OpenCVE Enrichment