Impact
NASA core Flight System (cFS) v7.0.1 contains an incorrect access control flaw in the Executive Services dynamic application start path component. The flaw permits an attacker to place a malicious shared object in a designated storage location, causing the system to load and execute the object. The result is arbitrary code execution on the target platform, potentially compromising confidentiality, integrity, and availability. The weakness maps to the category of improper authorization and controls.
Affected Systems
This vulnerability affects the NASA core Flight System (cFS) version 7.0.1. No other versions or products are listed; thus only installations of cFS 7.0.1 are impacted. The specific component is the dynamic application start path inside Executive Services, which determines where shared objects are loaded.
Risk and Exploitability
The CVSS score is not provided, but the description indicates a severe remote code execution risk. The EPSS score is not available, and the vulnerability is not in the CISA KEV catalog. With no published patch, exploitation would require an attacker to have write access to the storage location used by the dynamic application loader. The likely attack vector is via any mechanism that grants the attacker the ability to drop a shared object into that path, followed by an exploit of the loader to execute it.
OpenCVE Enrichment