« Back to list

Nasa

Nasa CFS: vulnerabilities and CVEs

Nasa CFS has 9 published vulnerabilities, 9 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs9
Last 12 months9
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-82480Medium (5.3)0.38%—Aug 30, 2026
A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c of the component cFE Software Bus.…
CVE-2026-82479Medium (5.3)0.38%—Aug 30, 2026
A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the component SBN TCP Module. Such manipulation of the argument MsgSz…
CVE-2026-67978High (7.5)0.46%—Aug 3, 2026
An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN frame.
CVE-2026-67975High (7.5)0.36%—Aug 3, 2026
Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands.
CVE-2026-67974High (7.5)0.53%—Aug 3, 2026
A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via sending a crafted packet.
CVE-2026-67973High (7.5)0.49%—Aug 3, 2026
An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.
CVE-2026-67970High (7.5)0.39%—Aug 3, 2026
Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal.
CVE-2026-67969High (7.5)0.38%—Aug 3, 2026
An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.AppMon_Tbl entry.
CVE-2026-67972High (7.5)0.44%—Aug 3, 2026
An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and data is stored, possibly leading to an information disclosure.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application7
  2. T1005 Data from Local System2
  3. T1499 Endpoint Denial of Service2
  4. T1499.004 Application or System Exploitation2
  5. T1565.002 Transmitted Data Manipulation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Nasa