Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-60112

Опубликовано: 29 июл. 2026
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() without any credential check. Attackers can exploit the unauthenticated session issuance in Sessions.create() and subsequently invoke handle_cmd() to forward arbitrary commands directly to the AIT command bus without any authentication gate between session creation and command dispatch.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nasa:ait_gui:*:*:*:*:*:*:*:*
Версия до 2.5.1 (исключая)

EPSS

Процентиль: 34%
0.00408
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 9.8
github
25 дней назад

AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() without any credential check. Attackers can exploit the unauthenticated session issuance in Sessions.create() and subsequently invoke handle_cmd() to forward arbitrary commands directly to the AIT command bus without any authentication gate between session creation and command dispatch.

EPSS

Процентиль: 34%
0.00408
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-306