Description
An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.
Published: 2026-08-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In NASA cFS v7.0.1 a flaw in the CFDP receive path allows an adversary to replay the final CFDP PDU, which can cause the receiving subsystem to hang and result in a denial of service. The impact is that the affected component or the entire system becomes unresponsive to legitimate traffic, potentially interrupting critical data transfers and mission operations.

Affected Systems

The vulnerability is limited to the NASA Common Platform (cFS) version 7.0.1. Other releases are not listed as affected; a review of your cFS version is advised.

Risk and Exploitability

The CVSS score of 7.5 indicates a high‑severity vulnerability, while the EPSS score is less than 1%, implying a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. The attacker would likely need the ability to send or inject CFDP PDUs over the network and would need to replay the final packet; the attack does not appear to require privileged access or authentication, implying a network-based vector. The observed effect is a loss of availability, but no data exfiltration or compromise of confidentiality is indicated.

Generated by OpenCVE AI on August 5, 2026 at 16:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Identify the version of cFS installed and confirm if it is 7.0.1 or earlier.
  • Upgrade to the latest cFS release once the official fix is issued by NASA.
  • If an upgrade is not immediately possible, implement application‑level replay checks: verify sequence numbers or timestamps on incoming CFDP PDUs and reject duplicate final packets.
  • Configure network access controls or firewall rules to restrict CFDP traffic to trusted hosts and monitor for repeated final PDU patterns that may indicate an attack.

Generated by OpenCVE AI on August 5, 2026 at 16:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via Replay of Final CFDP PDUs in NASA cFS 7.0.1

Wed, 05 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via Replay of Final CFDP PDUs in NASA cFS 7.0.1
Weaknesses CWE-400

Mon, 03 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Nasa
Nasa cfs
Vendors & Products Nasa
Nasa cfs

Mon, 03 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-05T15:09:00.910Z

Reserved: 2026-07-30T00:00:00.000Z

Link: CVE-2026-67973

cve-icon Vulnrichment

Updated: 2026-08-05T15:08:56.316Z

cve-icon NVD

Status : Received

Published: 2026-08-03T22:16:51.367

Modified: 2026-08-05T16:17:00.340

Link: CVE-2026-67973

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T17:00:12Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption