Nasa Ammos · Ait-Core · CVE-2026-105105
**Name of the Vulnerable Software and Affected Versions**
NASA-AMMOS AIT-Core versions prior to 3.1.2
**Description**
The `ait.core.server` telemetry and command broker (ait-server) lacks authentication for critical functions. By default, the ZeroMQ message bus binds its XSUB and XPUB sockets to all network interfaces without authentication or transport security. An attacker with network access to TCP port 5559 can publish messages to internal topics, such as the ` commands ` topic, which are then forwarded through the `command stream` and emitted on the command-uplink UDP path. Additionally, access to TCP port 5560 allows an attacker to subscribe to and exfiltrate command and telemetry traffic on the ground bus. This could lead to the injection of forged telemetry, the injection of spacecraft command data, or the disruption of the command and telemetry bus.
**Recommendations**
Update to version 3.1.2.
As a temporary mitigation, restrict network access to TCP ports 5559 and 5560 to prevent unauthorized access to the ZeroMQ message bus.