CRITICAL🇵🇱 Wersja polska

CVE-2024-54129

CVSS 9.2v4.0pub. 2024-12-05upd. 2026-04-15

The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A vulnerability exists in the version ION-DTN BPv7 implementation version 4.1.3 when receiving a bundle with an improper reference to the imc scheme with valid Service-Specific Part (SSP) in their Previous Node Block. The vulnerability can cause ION to become unresponsive. This vulnerability is fixed in 4.1.3s.

🤖 AI Analysis
How it works

The vulnerability is triggered when receiving a bundle (packet) containing an incorrect reference to the 'imc' scheme with a valid Service-Specific Part (SSP) placed in the Previous Node Block. Incorrect processing of such a packet in the BPv7 stack causes the ION process to enter an unresponsive state. An attacker can send a crafted packet remotely without requiring authentication, making the attack vector particularly dangerous.

Impact

An attacker can cause a denial of service (DoS) by immobilizing an ION-DTN node, resulting in interrupted DTN communication both locally and potentially in the overlay network (Interplanetary Overlay Network). In space mission environments or other critical applications, this may result in loss of connectivity with dependent systems.

Mitigation & patch

Update ION-DTN software to version 4.1.3s, where the vulnerability has been fixed. Patch is available in the vendor's repository: https://github.com/nasa-jpl/ION-DTN/security/advisories/GHSA-393w-w6jh-pq3j

Who is affected

NASA ION-DTN, BPv7 implementation version 4.1.3

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References