Impact
The vulnerability is a stack overflow located in the loadRawData function of the SpaceDot AcubeSAT OBC software. A crafted ECSS TC message can trigger the overflow, causing the in‑orbit computer to crash and halt. An attacker can cause this denial of service without any special privileges if the satellite’s communication link can be reached, potentially impacting mission-critical operations.
Affected Systems
SpaceDot AcubeSAT OBC software, specifically the code at commit eaf90ec, is affected. No vendor or patch level is listed, but any deployment of this software version is vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation. The attack vector is inferred to be remote, exploiting the ECSS TC message interface. As the vulnerability is a stack overflow, exploitation is likely feasible once an attacker can deliver a crafted message. The CISA KEV catalog does not list this CVE, so it is not known to have widespread exploitation yet, but the potential for service disruption remains significant.
OpenCVE Enrichment