« Back to list

Nasa

Nasa Fprime: vulnerabilities and CVEs

Nasa Fprime has 6 published vulnerabilities, 3 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.

CVEs6
Last 12 months3
Critical3
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-67977High (7.5)0.49%—Aug 3, 2026
An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2026-67976High (7.5)0.49%—Aug 3, 2026
The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allowing attackers to cause a Denial of Service (DoS) via inputting unsafe parameters.
CVE-2026-41144Critical (9.8)0.77%—Apr 22, 2026
F´ (F Prime) is a framework that enables development and deployment of spaceflight and other embedded software applications. Prior to version 4.2.0, the bounds check byteOffset + dataSize > fileSize uses U32 addition…
CVE-2024-55030Critical (9.8)1.8%—Mar 25, 2025
A command injection vulnerability in the Command Dispatcher Service of NASA Fprime v3.4.3 allows attackers to execute arbitrary commands.
CVE-2024-55029Medium (6.1)0.29%—Mar 25, 2025
NASA Fprime v3.4.3 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.
CVE-2024-55028Critical (9.8)0.79%—Mar 25, 2025
A template injection vulnerability in the Dashboard of NASA Fprime v3.4.3 allows attackers to execute arbitrary code via uploading a crafted Vue file.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application3
  2. T1059 Command and Scripting Interpreter1
  3. T1499 Endpoint Denial of Service1
  4. T1499.004 Application or System Exploitation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Nasa