Impact
A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 enables an attacker to cause a denial of service by sending a crafted packet to the SBN channel. The flaw may lead the peer subscription handler to terminate or become unresponsive, inferred from typical buffer or boundary violations that can disrupt process execution. The resulting crash or non‑responsive state disables the SBN peer subscription logic, potentially interrupting mission‑critical telemetry and overall flight‑aware communication.
Affected Systems
NASA’s core flight system (cFS) version 7.0.1, specifically the SBN application’s peer subscription message handling. No other vendors, products, or alternate versions are indicated in the CVE entry.
Risk and Exploitability
The CVSS score for this vulnerability is 7.5, indicating a high severity. Exploitation requires the ability to send a malicious packet to the target SBN service; no authentication or special privileges are mentioned. The EPSS score is listed as <1%, indicating a low but non‑zero likelihood of exploitation, and the vulnerability is not present in the CISA KEV catalog. Because the flaw can cause a service crash or hang, the impact on a mission‑critical system can be significant, but the overall risk is moderated by the low exploitation probability and the need for network reachability to the SBN channel.
OpenCVE Enrichment