Impact
The vulnerability is an out-of-bounds read/write that occurs within the MessageParser::parseECSSTCHeader component of the SpaceDot AcubeSAT on‑board computer firmware. An attacker can send a specially crafted CAN message that triggers the error, causing the OBC to crash or become unresponsive. Because the fault does not alter data or execute arbitrary code, the primary consequence is a loss of availability: the satellite would suffer a temporary or permanent denial of service until recovery procedures are executed.
Affected Systems
SpaceDot AcubeSAT’s OBC software is affected, specifically firmware that incorporates the commit eaf90ec. The vendor/product information is limited to the AcubeSAT OBC; no additional model or version identifiers are listed in the advisory. Operators of AcubeSAT missions should verify whether their deployed OBC firmware incorporates this commit or a newer patch.
Risk and Exploitability
The risk of exploitation depends on access to the satellite’s CAN bus. The vulnerability requires injection of a malicious CAN frame, implying a local or physical attack vector rather than a remote one. The CVSS score of 6.5 indicates moderate severity, and the EPSS score of <1% suggests a very low—but not zero—probability of exploitation. No public exploits or KEV listing are present. Nonetheless, since the DoS impact could jeopardize mission success, operators should treat this exposure with urgency and apply fixes as soon as they become available.
OpenCVE Enrichment