CVE-2026-60113
PoC nicheUnauthenticated API Access in NASA AMMOS AIT DSN SLE Interface
AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication flaw (CWE-306) in its Space Link Extension (SLE) interface manager, leaving seven API routes accessible without credentials. An unauthenticated network attacker triggers the issue simply by sending direct HTTP requests to the exposed SLE endpoints, requiring no privileges or user interaction. Successful access allows the attacker to start or stop Deep Space Network communication sessions, retrieve telemetry frame data, and inject arbitrary frames into active spacecraft links, potentially disrupting live mission communications. Only operators running AIT DSN Interface versions prior to 2.2.2 with the SLE interface manager reachable over a network are affected. No exploitation has been observed in the wild; the flaw carries a low EPSS score of 0.5% and a public advisory exists on the project's GitHub, but it is not listed in CISA KEV.
What to do: Upgrade AIT DSN Interface to version 2.2.2 or later to restore authentication on the seven SLE API routes. Until patched, restrict network access to the SLE interface manager (firewall rules, VPN, or allowlisting trusted ground-systems hosts) and monitor for unexpected session start/stop events or injected telemetry frames.
| nasa AIT Deep Space Network (DSN) Interface | all versions before 2.2.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network attackers to access seven unprotected API routes by sending direct HTTP requests with no credentials. Attackers can reach the exposed SLE endpoints to start or stop Deep Space Network communication sessions, retrieve telemetry frame data, and inject arbitrary frames into active spacecraft links.
- Vendors
- nasa
- Products
- ait dsn
- Weakness
- CWE-306
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.