cFS
by Nasa
CVEs (8)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-67979 | 0.00 | — | — | Aug 4, 2026 | Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage. | |||
| CVE-2026-67973 | 0.00 | — | 0.00 | Aug 3, 2026 | An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs. | |||
| CVE-2026-67970 | 0.00 | — | 0.00 | Aug 3, 2026 | Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal. | |||
| CVE-2026-67974 | 0.00 | — | 0.00 | Aug 3, 2026 | A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via sending a crafted packet. | |||
| CVE-2026-67978 | 0.00 | — | 0.00 | Aug 3, 2026 | An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN frame. | |||
| CVE-2026-67969 | 0.00 | — | 0.00 | Aug 3, 2026 | An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.AppMon_Tbl entry. | |||
| CVE-2026-67975 | 0.00 | — | 0.00 | Aug 3, 2026 | Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands. | |||
| CVE-2026-67972 | 0.00 | — | 0.00 | Aug 3, 2026 | An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and data is stored, possibly leading to an information disclosure. |
- CVE-2026-67979Aug 4, 2026risk 0.00cvss —epss —
Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage.
- CVE-2026-67973Aug 3, 2026risk 0.00cvss —epss 0.00
An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.
- CVE-2026-67970Aug 3, 2026risk 0.00cvss —epss 0.00
Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal.
- CVE-2026-67974Aug 3, 2026risk 0.00cvss —epss 0.00
A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via sending a crafted packet.
- CVE-2026-67978Aug 3, 2026risk 0.00cvss —epss 0.00
An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN frame.
- CVE-2026-67969Aug 3, 2026risk 0.00cvss —epss 0.00
An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.AppMon_Tbl entry.
- CVE-2026-67975Aug 3, 2026risk 0.00cvss —epss 0.00
Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands.
- CVE-2026-67972Aug 3, 2026risk 0.00cvss —epss 0.00
An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and data is stored, possibly leading to an information disclosure.