Skip to main content

Vendor/product archive

nasa / core_flight_system CVEs

Beta · best-effort

8 CVEs tagged to nasa / core_flight_system1 Critical, 3 High, 2 Medium, 2 Low, 0 Unrated.

CVE-2026-5476

Published Apr 3, 2026

A vulnerability was identified in NASA cFS up to 7.0.0 on 32-bit. Affected is the function CFE_TBL_ValidateCodecLoadSize of the file cfe/modules/tbl/fsw/src/cfe_tbl_passthru_codec…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2026-5475

Published Apr 3, 2026

A vulnerability was determined in NASA cFS up to 7.0.0. This impacts the function CFE_SB_TransmitMsg of the file cfe_sb_priv.c of the component CCSDS Header Size Handler. Executin…

CVSS 5.1 · Medium
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2026-5474

Published Apr 3, 2026

A vulnerability was found in NASA cFS up to 7.0.0. This affects the function CFE_MSG_GetSize of the file apps/to_lab/fsw/src/to_lab_passthru_encode.c of the component CCSDS Packet…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2026-5473

Published Apr 3, 2026

A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the component Pickle Module. Such manipulation leads to deserialization…

CVSS 1.1 · Low
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2025-25374

Published Mar 25, 2025

In NASA cFS (Core Flight System) Aquila, it is possible to put the onboard software in a state that will prevent the launch of any external application, causing a platform denial…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-25373

Published Mar 25, 2025

The Memory Management Module of NASA cFS (Core Flight System) Aquila has insecure permissions, which can be exploited to gain an RCE on the platform.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-25372

Published Mar 25, 2025

NASA cFS (Core Flight System) Aquila is vulnerable to segmentation fault via sending a malicious telecommand to the Memory Management Module.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-25371

Published Mar 25, 2025

NASA cFS (Core Flight System) Aquila is vulnerable to path traversal in the OSAL module, allowing the override of any arbitrary file on the system.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1