Description
An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN frame.
Published: 2026-08-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An issue in the Spaceβ Network (SBN) UDP interface of NASA's Core Flight System (cFS) version 7.0.1 allows an attacker to trigger a denial of service by sending a specially crafted SBN frame. The attack consumes resources in the cFS UDP processing path, causing the system to become unresponsive or to crash. Because the data path is part of the core flight environment, the impact can affect mission‑critical operations, disrupting both local and remote commands.

Affected Systems

The vulnerability affects the NASA Core Flight System (cFS) software, specifically release 7.0.1. No other versions are listed as impacted in the current advisory.

Risk and Exploitability

The exploit requires the ability to send UDP packets to a host running cFS with the SBN interface enabled. The assault vector is network‑based, transmitting a malicious SBN frame. The EPSS score is <1%, indicating a low exploitation probability, and the vulnerability is not currently listed in the CISA KEV catalog. The CVSS score of 7.5 indicates high severity; while the low EPSS suggests a modest likelihood of exploitation, the potential impact on mission‑critical operations warrants prompt remediation.

Generated by OpenCVE AI on August 4, 2026 at 21:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest cFS release that contains the SBN UDP fix
  • Restrict UDP access to the SBN interface to trusted networks or firewalls
  • Implement monitoring for abnormal UDP traffic or repeated SBN frames that could indicate attack

Generated by OpenCVE AI on August 4, 2026 at 21:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 04 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Title Crafted SBN Frame Causes DoS in NASA cFS v7.0.1
Weaknesses CWE-400

Mon, 03 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Nasa
Nasa cfs
Vendors & Products Nasa
Nasa cfs

Mon, 03 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Description An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN frame.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-04T19:42:48.867Z

Reserved: 2026-07-30T00:00:00.000Z

Link: CVE-2026-67978

cve-icon Vulnrichment

Updated: 2026-08-04T19:41:55.344Z

cve-icon NVD

Status : Received

Published: 2026-08-03T23:16:47.213

Modified: 2026-08-04T20:16:52.553

Link: CVE-2026-67978

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T22:00:07Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-400

    Uncontrolled Resource Consumption