Impact
The SpaceDot AcubeSAT OBC software contains an integer handling flaw in the cobs_decode routine. An attacker who can communicate with the satellite’s UART interface can construct a crafted packet that causes the decoder to misinterpret data lengths, leading to a crash of the OBC processing loop and a denial of service for the satellite’s onboard computer.
Affected Systems
Only the SpaceDot AcubeSAT OBC software at commit eaf90ec is affected. No other vendors or product versions are listed in the advisory.
Risk and Exploitability
The EPSS score is under 1% and the vulnerability is not listed in the CISA KEV catalogue. Because an exploit requires physical proximity and UART connectivity, the attack vector is limited to onsite manipulators with direct access to the OBC interface. With a CVSS score of 7.5, a successful denial of service could interrupt mission‑critical operations, making the flaw high‑risk for satellite missions.
OpenCVE Enrichment