W NASA cFS do wersji 7.0.0 wykryta została podatność w funkcji CFE_SB_TransmitMsg pliku cfe_sb_priv.c komponentu CCSDS Header Size Handler. Manipulacja może prowadzić do memory corruption. Projekt został poinformowany o problemie wcześnie poprzez raport, ale jeszcze na niego nie odpowiedział.
▸ Pokaż oryginał (EN)
A vulnerability was determined in NASA cFS up to 7.0.0. This impacts the function CFE_SB_TransmitMsg of the file cfe_sb_priv.c of the component CCSDS Header Size Handler. Executing a manipulation can lead to memory corruption. The project was informed of the problem early through an issue report but has not responded yet.
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XNasa Core Flight System
APPNasa≤ 7.0.0
Powiązane podatności
NASA cFS Aquila — błędne uprawnienia w module zarządzania pamięcią umożliwiają RCE
NASA cFS (Core Flight System) Aquila is vulnerable to segmentation fault via sending a malicious telecommand t...
NASA cFS (Core Flight System) Aquila is vulnerable to path traversal in the OSAL module, allowing the override...
In NASA cFS (Core Flight System) Aquila, it is possible to put the onboard software in a state that will preve...
W NASA cFS do wersji 7.0.0 znaleziono podatność w funkcji CFE_MSG_GetSize pliku apps/to_lab/fsw/src/to_lab_pas...