PT-2024-26305 · Nasa · Nasa Ait-Core

Andy Olchawa

+1

·

Published

2024-05-21

·

Updated

2024-07-17

·

CVE-2024-35061

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions NASA AIT-Core version 2.5.2
Description The issue allows attackers to execute a man-in-the-middle attack due to the use of unencrypted channels for data exchange over the network. This can lead to unauthenticated, fully remote code execution when combined with other vulnerabilities.
Recommendations For NASA AIT-Core version 2.5.2, consider implementing encrypted communication channels to prevent man-in-the-middle attacks. As a temporary workaround, restrict network access to trusted sources until a patch is available.

Exploit

Fix

Missing Encryption of Sensitive Data

Special Elements Injection

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-35061
GHSA-JQFF-8G2V-642H
GHSA-QV6X-53JJ-VW59

Affected Products

Nasa Ait-Core