PT-2026-65835 · Unknown · Ammos Instrument Toolkit (Ait) Deep Space Network (Dsn) Interface
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface versions prior to 2.2.2
Description
The Space Link Extension (SLE) interface manager lacks proper authentication, allowing unauthenticated network attackers to access seven unprotected API routes via direct HTTP requests. This allows attackers to start or stop Deep Space Network communication sessions, retrieve telemetry frame data, and inject arbitrary frames into active spacecraft links.
Recommendations
Update AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface to version 2.2.2 or later.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ammos Instrument Toolkit (Ait) Deep Space Network (Dsn) Interface