Impact
The missing authentication flaw in the Space Link Extension (SLE) interface manager of AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) allows unauthenticated attackers to reach seven exposed HTTP endpoints. By sending direct requests without credentials, an attacker can start or stop DSN communication sessions, retrieve telemetry frame data, and inject arbitrary frames into active spacecraft links. This ability to manipulate mission‑critical communications without authorization corresponds to CWE‑306 and can lead to severe confidentiality, integrity, and availability problems for space missions.
Affected Systems
The vulnerability affects NASA‑AMMOS’s AIT‑DSN product, specifically all releases prior to version 2.2.2. No other versions are known to be impacted according to the vendor’s advisories.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity, while the EPSS score of less than 1% suggests that, at present, the likelihood of exploitation in the wild is low. The vulnerability is not listed in CISA’s KEV catalog. However, because it is a remote unauthenticated API flaw, an attacker who can reach the exposed endpoints over the network can exploit it immediately by crafting HTTP calls, without needing any special credentials or privileged access. The high severity combined with open internet exposure makes it a priority for mitigation.
OpenCVE Enrichment