Impact
In NASA cFS v7.0.1 a flaw in the CFDP receive path allows an adversary to replay the final CFDP PDU, which can cause the receiving subsystem to hang and result in a denial of service. The impact is that the affected component or the entire system becomes unresponsive to legitimate traffic, potentially interrupting critical data transfers and mission operations.
Affected Systems
The vulnerability is limited to the NASA Common Platform (cFS) version 7.0.1. Other releases are not listed as affected; a review of your cFS version is advised.
Risk and Exploitability
The CVSS score of 7.5 indicates a high‑severity vulnerability, while the EPSS score is less than 1%, implying a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. The attacker would likely need the ability to send or inject CFDP PDUs over the network and would need to replay the final packet; the attack does not appear to require privileged access or authentication, implying a network-based vector. The observed effect is a loss of availability, but no data exfiltration or compromise of confidentiality is indicated.
OpenCVE Enrichment