Impact
This vulnerability occurs in the decodeSdnv function of ION-DTN versions before 4.2.0. Unauthenticated remote attackers can send a truncated SDNV in a UDP datagram to the LTP link service input port. The function then performs an out-of-bounds read that can retrieve up to nine bytes beyond the intended buffer, enabling the attacker to read arbitrary memory contents. A memory disclosure can lead to sensitive data leakage or aid further attacks.
Affected Systems
The affected product is NASA JPL’s ION‑DTN software, available before release 4.2.0. Any deployment running versions such as 4.1.x or earlier is vulnerable. The vulnerability resides within the core library used by the LTP link service.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. No EPSS data is available, and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Attackers can exploit the flaw remotely by sending a malicious UDP packet; the flaw does not require privileges or authentication, making it readily actionable in uncontrolled networks.
OpenCVE Enrichment