Impact
An OS command injection flaw exists in NASA HyperCP’s data download handler, which parses server response headers without sanitization and forwards attacker-controlled values to subprocess calls. The vulnerability allows an attacker who can intercept or spoof responses from the public data server <ftps://oceandata.sci.gsfc.nasa.gov> to execute arbitrary system commands on the researcher’s workstation during a data download operation. This flaw originates from the CWE-78 weakness in the OBPGSession.py module, granting a full code‑execution compromise of the affected system.
Affected Systems
NASA HyperCP (main branch). Version information is not specified in the advisory, so all current installations of HyperCP are potentially vulnerable until a fix is applied.
Risk and Exploitability
The CVSS score of 7.5 signals a high‑impact vulnerability. Although EPSS data is not provided, the attack requires a network‑adjacent attacker capable of tampering with HTTP responses. The vulnerability is not listed in CISA’s KEV catalog, but exploitation remains feasible if an attacker can compromise network traffic to the data server. Attackers could leverage this flaw to gain full system compromise on the client’s workstation.
OpenCVE Enrichment