NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
ID: 7e155cc4-4f35-5945-b0ed-91733a3a8411
STIX ID: report--7e155cc4-4f35-5945-b0ed-91733a3a8411
Feed Name: The Hacker News
Cycode disclosed a high-severity chain of flaws (GHSA-p9r8-2q67-fp86, CVSS 9.4) in AIT-GUI that allow unauthenticated acquisition of a session cookie and subsequent arbitrary spacecraft/instrument commanding, path traversal to run server-side scripts, and cross-origin POST delivery enabling CSRF-like attacks; fixes were released in 2.5.2 to restrict binding and block browser-driven cross-origin requests but credential-based authentication for command/script/sequence endpoints remains absent and records disagree on exact fixed versions and scope.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
