Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-43rr-mfcw-532v

Опубликовано: 03 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 6.3

Описание

A vulnerability was found in NASA cFS up to 7.0.0. This affects the function CFE_MSG_GetSize of the file apps/to_lab/fsw/src/to_lab_passthru_encode.c of the component CCSDS Packet Header Handler. Performing a manipulation results in heap-based buffer overflow. The attacker must have access to the local network to execute the attack. The project was informed of the problem early through an issue report but has not responded yet.

A vulnerability was found in NASA cFS up to 7.0.0. This affects the function CFE_MSG_GetSize of the file apps/to_lab/fsw/src/to_lab_passthru_encode.c of the component CCSDS Packet Header Handler. Performing a manipulation results in heap-based buffer overflow. The attacker must have access to the local network to execute the attack. The project was informed of the problem early through an issue report but has not responded yet.

EPSS

Процентиль: 3%
0.00015
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 6.3
nvd
4 дня назад

A vulnerability was found in NASA cFS up to 7.0.0. This affects the function CFE_MSG_GetSize of the file apps/to_lab/fsw/src/to_lab_passthru_encode.c of the component CCSDS Packet Header Handler. Performing a manipulation results in heap-based buffer overflow. The attacker must have access to the local network to execute the attack. The project was informed of the problem early through an issue report but has not responded yet.

EPSS

Процентиль: 3%
0.00015
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-119