Impact
NASA’s core Flight System (cFS) version 7.0.1 contains an incorrect access‑control flaw that permits an attacker to send TO_LAB add or remove subscription commands and arbitrarily delete low‑index subscriptions or create new telemetry streams. This flaw enables a remote adversary to disrupt mission telemetry by dropping legitimate streams or injecting unauthorized ones, potentially leading to loss of critical data, degraded situational awareness, or denial of service for downstream systems that rely on those streams.
Affected Systems
The vulnerability is confined to NASA’s core Flight System version 7.0.1, an open‑source software platform used in spaceflight and aeronautics applications. No other vendors, products or version ranges are currently reported as affected.
Risk and Exploitability
The flaw arises from a lack of proper authorization checks in the subscription handling component. An attacker who can reach the cFS command interface can exploit the weakness without needing elevated privileges or additional credentials. Given the CVSS score of 7.5 and an EPSS score of <1%, exploitation likelihood remains low but the control of telemetry streams is a critical capability, and the vulnerability is not yet in CISA’s KEV catalog. The attack vector is inferred to be remote command injection over the cFS communication link, requiring network connectivity to the spacecraft or ground segment that hosts the cFS instance.
OpenCVE Enrichment