Impact
A buffer overflow exists in the OS_read function of the SBN TCP Module in NASA cFS versions up to 7.0.1. The flaw is triggered by manipulating the MsgSz parameter, which leads to uncontrolled memory writes. An attacker who can send crafted TCP packets from the local network could overwrite adjacent memory, potentially gaining code execution or causing a denial of service. The vulnerability is confined to local network traffic and does not appear to be exploitable from the Internet.
Affected Systems
NASA Core Flight System (cFS), specifically the SBN TCP Module component. All installations running version 7.0.1 or earlier are affected; later releases are presumed patched.
Risk and Exploitability
The CVSS score of 5.3 categorizes the issue as medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires local network access, so the risk is primarily to insiders or compromised devices within the network. Without a patch or mitigation, an attacker could achieve memory corruption that may lead to partial control or service interruption. Because the attack vector is limited to local traffic, external exposure is unlikely, but internal threats remain significant.
OpenCVE Enrichment