VYPR

cFS

by Nasa

Source repositories

CVEs (14)

  • CVE-2026-67979CriAug 4, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage.

  • CVE-2026-67978HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN frame.

  • CVE-2026-67975HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands.

  • CVE-2026-67974HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via sending a crafted packet.

  • CVE-2026-67973HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.

  • CVE-2026-67970HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal.

  • CVE-2026-67969HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.AppMon_Tbl entry.

  • CVE-2026-67972HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and data is stored, possibly leading to an information disclosure.

  • CVE-2026-82480HigAug 30, 2026
    risk 0.48cvss 7.4epss 0.00

    A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c of the component cFE Software Bus. Performing a manipulation of the argument TotalMsgSize/HdrSize…

  • CVE-2026-82479MedAug 30, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the component SBN TCP Module. Such manipulation of the argument MsgSz leads to buffer overflow. The attack must be carried out from…

  • CVE-2026-5474MedApr 3, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability was found in NASA cFS up to 7.0.0. This affects the function CFE_MSG_GetSize of the file apps/to_lab/fsw/src/to_lab_passthru_encode.c of the component CCSDS Packet Header Handler. Performing a manipulation results in heap-based buffer overflow. The attacker must…

  • CVE-2026-5475MedApr 3, 2026
    risk 0.29cvss 5.5epss 0.00

    A vulnerability was determined in NASA cFS up to 7.0.0. This impacts the function CFE_SB_TransmitMsg of the file cfe_sb_priv.c of the component CCSDS Header Size Handler. Executing a manipulation can lead to memory corruption. The project was informed of the problem early…

  • CVE-2026-5476MedApr 3, 2026
    risk 0.23cvss 4.6epss 0.00

    A vulnerability was identified in NASA cFS up to 7.0.0 on 32-bit. Affected is the function CFE_TBL_ValidateCodecLoadSize of the file cfe/modules/tbl/fsw/src/cfe_tbl_passthru_codec.c. The manipulation leads to integer overflow. The complexity of an attack is rather high. The…

  • CVE-2026-5473MedApr 3, 2026
    risk 0.22cvss 4.5epss 0.00

    A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the component Pickle Module. Such manipulation leads to deserialization. The attack needs to be performed locally. The attack requires a high level of complexity. The…