Description
A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via sending a crafted packet.
Published: 2026-08-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 enables an attacker to cause a denial of service by sending a crafted packet to the SBN channel. The flaw may lead the peer subscription handler to terminate or become unresponsive, inferred from typical buffer or boundary violations that can disrupt process execution. The resulting crash or non‑responsive state disables the SBN peer subscription logic, potentially interrupting mission‑critical telemetry and overall flight‑aware communication.

Affected Systems

NASA’s core flight system (cFS) version 7.0.1, specifically the SBN application’s peer subscription message handling. No other vendors, products, or alternate versions are indicated in the CVE entry.

Risk and Exploitability

The CVSS score for this vulnerability is 7.5, indicating a high severity. Exploitation requires the ability to send a malicious packet to the target SBN service; no authentication or special privileges are mentioned. The EPSS score is listed as <1%, indicating a low but non‑zero likelihood of exploitation, and the vulnerability is not present in the CISA KEV catalog. Because the flaw can cause a service crash or hang, the impact on a mission‑critical system can be significant, but the overall risk is moderated by the low exploitation probability and the need for network reachability to the SBN channel.

Generated by OpenCVE AI on August 13, 2026 at 10:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade cFS to a newer release that incorporates the SBN boundary check fix.
  • If an immediate upgrade is not possible, limit network traffic to the SBN port to a trusted set of peers and configure firewalls or routers to block packets that exceed expected sizes or originate from untrusted sources.
  • Enable detailed logging for the SBN application and monitor logs for frequent crashes, abnormal packet sizes, or other indicators of malformed messages.

Generated by OpenCVE AI on August 13, 2026 at 10:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via Parser Boundary Flaw in NASA cFS SBN Peer Subscription Handling

Wed, 12 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via Crafted Packet Exploiting Parser Boundary Flaw in NASA cFS v7.0.1
Weaknesses CWE-119

Tue, 04 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Crafted Packet Exploiting Parser Boundary Flaw in NASA cFS v7.0.1
Weaknesses CWE-119
CWE-20

Tue, 04 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Nasa
Nasa cfs
Vendors & Products Nasa
Nasa cfs

Mon, 03 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via sending a crafted packet.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-06T15:38:10.893Z

Reserved: 2026-07-30T00:00:00.000Z

Link: CVE-2026-67974

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-03T22:16:51.487

Modified: 2026-08-06T22:18:24.030

Link: CVE-2026-67974

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:15:07Z

Weaknesses
  • CWE-20

    Improper Input Validation