PT-2026-104572 · Nasa Ammos · Ait-Core
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NASA-AMMOS AIT-Core versions prior to 3.1.2
Description
The
ait.core.server telemetry and command broker (ait-server) lacks authentication for critical functions. By default, the ZeroMQ message bus binds its XSUB and XPUB sockets to all network interfaces without authentication or transport security. An attacker with network access to TCP port 5559 can publish messages to internal topics, such as the commands topic, which are then forwarded through the command stream and emitted on the command-uplink UDP path. Additionally, access to TCP port 5560 allows an attacker to subscribe to and exfiltrate command and telemetry traffic on the ground bus. This could lead to the injection of forged telemetry, the injection of spacecraft command data, or the disruption of the command and telemetry bus.Recommendations
Update to version 3.1.2.
As a temporary mitigation, restrict network access to TCP ports 5559 and 5560 to prevent unauthorized access to the ZeroMQ message bus.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ait-Core