Impact
The HS_MonitorApplications() component of NASA Core Flight System (cFS) contains an improper input validation flaw (CWE-20). A crafted entry added to the HS.AppMon_Tbl triggers a forced processor reset. The reset halts the flight software, terminating all running processes and causing a denial‑of‑service condition. The impact is limited to loss of functionality and potential loss of mission‑critical data, but no data exfiltration or compromise of code execution is described. The flaw does not require privilege escalation beyond the ability to write to HS.AppMon_Tbl, which may be local or remote depending on system configuration.
Affected Systems
NASA Core Flight System version 7.0.1 is affected. The vulnerability resides in the HS_MonitorApplications() component; any deployment of this cFS version that includes the component is at risk. No additional product or version information is provided in the CVE data.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EPSS score of < 1% shows a low but nonzero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog, which suggests it has not been widely exploited yet. The attack vector is likely local or remote write access to HS.AppMon_Tbl; no complex prerequisites are described. Because the flaw requires only crafted data, the risk of exploitation is moderate to high, especially in environments where HS.AppMon_Tbl can be altered by untrusted actors.
OpenCVE Enrichment