Impact
DS_SetDestPathCmd in NASA Core Flight System 7.0.1 has a flaw where incorrect access control (CWE-284: Improper Access Control) permits a path traversal that allows an attacker to craft command requests to manipulate destination paths and read or modify files outside the designated directory. The weakness involves insufficient authorization, resulting in unauthorized access to sensitive components.
Affected Systems
NASA Core Flight System version 7.0.1, specifically its DS_SetDestPathCmd command component.
Risk and Exploitability
The CVSS score of 7.5 indicates moderate to high severity, and the EPSS score of less than 1% shows a low likelihood of exploitation currently. Because the description does not specify whether the cFS instance is network reachable, it is inferred that a reachable interface would enable exploitation. The vulnerability is not listed in the CISA KEV catalog, so no confirmed exploits are known; operators should treat the issue as a priority for patching to prevent unauthorized file system access.
OpenCVE Enrichment