PT-2024-26305 · Nasa · Nasa Ait-Core
Andy Olchawa
+1
·
Published
2024-05-21
·
Updated
2024-07-17
·
CVE-2024-35061
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
NASA AIT-Core version 2.5.2
Description
The issue allows attackers to execute a man-in-the-middle attack due to the use of unencrypted channels for data exchange over the network. This can lead to unauthenticated, fully remote code execution when combined with other vulnerabilities.
Recommendations
For NASA AIT-Core version 2.5.2, consider implementing encrypted communication channels to prevent man-in-the-middle attacks. As a temporary workaround, restrict network access to trusted sources until a patch is available.
Exploit
Fix
Missing Encryption of Sensitive Data
Special Elements Injection
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nasa Ait-Core