PT-2026-104572 · Nasa Ammos · Ait-Core

·

CVE-2026-105105

·

Published

2026-10-03

·

Updated

2026-10-04

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NASA-AMMOS AIT-Core versions prior to 3.1.2
Description The ait.core.server telemetry and command broker (ait-server) lacks authentication for critical functions. By default, the ZeroMQ message bus binds its XSUB and XPUB sockets to all network interfaces without authentication or transport security. An attacker with network access to TCP port 5559 can publish messages to internal topics, such as the commands topic, which are then forwarded through the command stream and emitted on the command-uplink UDP path. Additionally, access to TCP port 5560 allows an attacker to subscribe to and exfiltrate command and telemetry traffic on the ground bus. This could lead to the injection of forged telemetry, the injection of spacecraft command data, or the disruption of the command and telemetry bus.
Recommendations Update to version 3.1.2. As a temporary mitigation, restrict network access to TCP ports 5559 and 5560 to prevent unauthorized access to the ZeroMQ message bus.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105105

Affected Products

Ait-Core