VYPR
Vendor

NASA AMMOS

Products
6
CVEs
5
Across products
5
Status
Private

Products

6

Recent CVEs

5
  • CVE-2026-71289CriAug 5, 2026
    risk 0.64cvss 9.8epss 0.00

    The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. ":8089/tcp") with cap_add: NET_ADMIN, NET_RAW, SYS_NICE,…

  • CVE-2026-71214CriAug 5, 2026
    risk 0.64cvss 9.8epss 0.00

    The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession, which prefers a session_variables object taken directly from the client-supplied JSON request body over the Authorization…

  • CVE-2026-60113CriJul 29, 2026
    risk 0.64cvss 9.8epss 0.01

    AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network attackers to access seven unprotected API routes by sending…

  • CVE-2026-60112CriJul 29, 2026
    risk 0.64cvss 9.8epss 0.01

    AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() without any credential check. Attackers…

  • CVE-2026-47731CriJul 21, 2026
    risk 0.52cvss 9.1epss 0.01

    The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS)) is a Python-based software suite developed to handle Ground Data System (GDS), Electronic Ground Support Equipment (EGSE), commanding, telemetry uplink/downlink, and sequencing…