Description
An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.AppMon_Tbl entry.
Published: 2026-08-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The HS_MonitorApplications() component of NASA Core Flight System (cFS) contains an improper input validation flaw (CWE-20). A crafted entry added to the HS.AppMon_Tbl triggers a forced processor reset. The reset halts the flight software, terminating all running processes and causing a denial‑of‑service condition. The impact is limited to loss of functionality and potential loss of mission‑critical data, but no data exfiltration or compromise of code execution is described. The flaw does not require privilege escalation beyond the ability to write to HS.AppMon_Tbl, which may be local or remote depending on system configuration.

Affected Systems

NASA Core Flight System version 7.0.1 is affected. The vulnerability resides in the HS_MonitorApplications() component; any deployment of this cFS version that includes the component is at risk. No additional product or version information is provided in the CVE data.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. The EPSS score of < 1% shows a low but nonzero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog, which suggests it has not been widely exploited yet. The attack vector is likely local or remote write access to HS.AppMon_Tbl; no complex prerequisites are described. Because the flaw requires only crafted data, the risk of exploitation is moderate to high, especially in environments where HS.AppMon_Tbl can be altered by untrusted actors.

Generated by OpenCVE AI on August 12, 2026 at 00:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade NASA cFS to a version that patches the HS_MonitorApplications() reset issue
  • Restrict write permissions on HS.AppMon_Tbl so that only trusted or privileged processes may modify it, mitigating improper input exposure
  • Modify the source code to validate every entry in HS.AppMon_Tbl before using it, ensuring malformed data cannot trigger a processor reset

Generated by OpenCVE AI on August 12, 2026 at 00:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Force Processor Reset via Crafted HS Monitor Applications Entry in NASA cFS

Tue, 04 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Title Force Processor Reset via Crafted HS Monitor Applications Entry in NASA cFS
Weaknesses CWE-20

Tue, 04 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Nasa
Nasa cfs
Vendors & Products Nasa
Nasa cfs

Mon, 03 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.AppMon_Tbl entry.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-06T15:38:23.906Z

Reserved: 2026-07-30T00:00:00.000Z

Link: CVE-2026-67969

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-03T22:16:51.110

Modified: 2026-08-06T22:18:23.523

Link: CVE-2026-67969

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T01:00:04Z

Weaknesses
  • CWE-20

    Improper Input Validation