Impact
An issue in the Spaceβ Network (SBN) UDP interface of NASA's Core Flight System (cFS) version 7.0.1 allows an attacker to trigger a denial of service by sending a specially crafted SBN frame. The attack consumes resources in the cFS UDP processing path, causing the system to become unresponsive or to crash. Because the data path is part of the core flight environment, the impact can affect mission‑critical operations, disrupting both local and remote commands.
Affected Systems
The vulnerability affects the NASA Core Flight System (cFS) software, specifically release 7.0.1. No other versions are listed as impacted in the current advisory.
Risk and Exploitability
The exploit requires the ability to send UDP packets to a host running cFS with the SBN interface enabled. The assault vector is network‑based, transmitting a malicious SBN frame. The EPSS score is <1%, indicating a low exploitation probability, and the vulnerability is not currently listed in the CISA KEV catalog. The CVSS score of 7.5 indicates high severity; while the low EPSS suggests a modest likelihood of exploitation, the potential impact on mission‑critical operations warrants prompt remediation.
OpenCVE Enrichment