Description
Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal.
Published: 2026-08-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

DS_SetDestPathCmd in NASA Core Flight System 7.0.1 has a flaw where incorrect access control (CWE-284: Improper Access Control) permits a path traversal that allows an attacker to craft command requests to manipulate destination paths and read or modify files outside the designated directory. The weakness involves insufficient authorization, resulting in unauthorized access to sensitive components.

Affected Systems

NASA Core Flight System version 7.0.1, specifically its DS_SetDestPathCmd command component.

Risk and Exploitability

The CVSS score of 7.5 indicates moderate to high severity, and the EPSS score of less than 1% shows a low likelihood of exploitation currently. Because the description does not specify whether the cFS instance is network reachable, it is inferred that a reachable interface would enable exploitation. The vulnerability is not listed in the CISA KEV catalog, so no confirmed exploits are known; operators should treat the issue as a priority for patching to prevent unauthorized file system access.

Generated by OpenCVE AI on August 13, 2026 at 10:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest cFS release that fixes the DS_SetDestPathCmd path traversal flaw, such as upgrading to v7.0.2 or later if available.
  • If an immediate upgrade is not possible, restrict the cFS process file permissions and enforce a read‑only, bounded directory tree to deny traversal outside the allowed space.
  • Configure system confinement mechanisms (e.g., SELinux, AppArmor, or container isolation) to limit the cFS service’s filesystem access to only the necessary directory hierarchy.
  • Monitor cFS logs for abnormal path requests and review access patterns for signs of exploitation attempts.

Generated by OpenCVE AI on August 13, 2026 at 10:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 13 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in NASA cFS DS_SetDestPathCmd Command

Wed, 12 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Exploitation of NASA cFS DS_SetDestPathCmd
Weaknesses CWE-22
CWE-285

Tue, 04 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Exploitation of NASA cFS DS_SetDestPathCmd
Weaknesses CWE-22
CWE-285

Mon, 03 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Nasa
Nasa cfs
Vendors & Products Nasa
Nasa cfs

Mon, 03 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-06T15:38:17.730Z

Reserved: 2026-07-30T00:00:00.000Z

Link: CVE-2026-67970

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-03T22:16:51.237

Modified: 2026-08-06T22:18:23.693

Link: CVE-2026-67970

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T11:00:12Z

Weaknesses