Description
An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically-proximate attackers with UART access to cause a Denial of Service (DoS) via a crafted input.
Published: 2026-08-24
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Mitigation
AI Analysis

Impact

The SpaceDot AcubeSAT OBC software contains an integer handling flaw in the cobs_decode routine. An attacker who can communicate with the satellite’s UART interface can construct a crafted packet that causes the decoder to misinterpret data lengths, leading to a crash of the OBC processing loop and a denial of service for the satellite’s onboard computer.

Affected Systems

Only the SpaceDot AcubeSAT OBC software at commit eaf90ec is affected. No other vendors or product versions are listed in the advisory.

Risk and Exploitability

The EPSS score is under 1% and the vulnerability is not listed in the CISA KEV catalogue. Because an exploit requires physical proximity and UART connectivity, the attack vector is limited to onsite manipulators with direct access to the OBC interface. With a CVSS score of 7.5, a successful denial of service could interrupt mission‑critical operations, making the flaw high‑risk for satellite missions.

Generated by OpenCVE AI on August 26, 2026 at 06:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Implement a validation check to verify the size and integrity of each incoming COBS packet before invoking cobs_decode, thereby preventing malformed inputs from causing errors.
  • Physically secure the UART port or restrict access to authorized personnel during non‑critical periods to limit the window for a local attack.
  • Check the SpaceDot vendor’s website, repository, or update distribution for a firmware release that addresses the integer handling bug and apply any available patch or update when it becomes available.

Generated by OpenCVE AI on August 26, 2026 at 06:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 26 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Integer Overrun in COBS Decoder Enables UART‑Based Denial of Service on AcubeSAT OBC

Wed, 26 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title SpaceDot AcubeSAT UART Denial of Service via Integer Handling Flaw in cobs_decode
Weaknesses CWE-198

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Spacedot
Spacedot acubesat
Vendors & Products Spacedot
Spacedot acubesat

Mon, 24 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title SpaceDot AcubeSAT UART Denial of Service via Integer Handling Flaw in cobs_decode
Weaknesses CWE-198

Mon, 24 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically-proximate attackers with UART access to cause a Denial of Service (DoS) via a crafted input.
References

Subscriptions

Spacedot Acubesat
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-25T19:44:01.570Z

Reserved: 2026-08-17T00:00:00.000Z

Link: CVE-2026-75371

cve-icon Vulnrichment

Updated: 2026-08-25T19:43:58.203Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T19:16:58.310

Modified: 2026-09-09T16:04:24.933

Link: CVE-2026-75371

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T06:30:16Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption