ZeroHour

CVE-2026-60113

PoC niche

Unauthenticated API Access in NASA AMMOS AIT DSN SLE Interface

CVSS 4.0
9.3 critical
EPSS
<1%p43
Published
()
Modified
AI analysis

AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication flaw (CWE-306) in its Space Link Extension (SLE) interface manager, leaving seven API routes accessible without credentials. An unauthenticated network attacker triggers the issue simply by sending direct HTTP requests to the exposed SLE endpoints, requiring no privileges or user interaction. Successful access allows the attacker to start or stop Deep Space Network communication sessions, retrieve telemetry frame data, and inject arbitrary frames into active spacecraft links, potentially disrupting live mission communications. Only operators running AIT DSN Interface versions prior to 2.2.2 with the SLE interface manager reachable over a network are affected. No exploitation has been observed in the wild; the flaw carries a low EPSS score of 0.5% and a public advisory exists on the project's GitHub, but it is not listed in CISA KEV.

What to do: Upgrade AIT DSN Interface to version 2.2.2 or later to restore authentication on the seven SLE API routes. Until patched, restrict network access to the SLE interface manager (firewall rules, VPN, or allowlisting trusted ground-systems hosts) and monitor for unexpected session start/stop events or injected telemetry frames.

Affected
nasa AIT Deep Space Network (DSN) Interfaceall versions before 2.2.2
Estimated exposure
nichelikely tens to low hundreds of deployments (specialized NASA mission-operations toolkit, no public install counts) — AIT DSN is a niche open-source toolkit used by a small number of space missions and ground-data operations teams rather than mass-market software, so only a small population of internet- or network-exposed instances is plausible, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network attackers to access seven unprotected API routes by sending direct HTTP requests with no credentials. Attackers can reach the exposed SLE endpoints to start or stop Deep Space Network communication sessions, retrieve telemetry frame data, and inject arbitrary frames into active spacecraft links.

Vendors
nasa
Products
ait dsn
Weakness
CWE-306
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.