Impact
The vulnerability is a NULL pointer dereference that causes a segmentation fault when a routine Housekeeping Telemetry request is processed. The crash brings down the Health & Safety application, resulting in loss of telemetry and availability for other components that depend on it. It does not expose data or allow code execution, but it produces a denial of service.
Affected Systems
All installations of NASA's Core Flight System Health & Safety application that are running a version earlier than 7.0.1 are affected. The patch is available in the NASA GitHub HS repository as version 7.0.1, which updates the HS component.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity. The EPSS score of less than 1% suggests that exploitation is considered unlikely at this time, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an attacker injecting a malformed Housekeeping Telemetry packet that triggers the null dereference; external exposure or network access details are not provided.
OpenCVE Enrichment