CVE-2026-60113
CRITICALNASA-AMMOS AIT-DSN < 2.2.2 - Missing Authentication in SLE API Routes
Title source: manualDescription
AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network attackers to access seven unprotected API routes by sending direct HTTP requests with no credentials. Attackers can reach the exposed SLE endpoints to start or stop Deep Space Network communication sessions, retrieve telemetry frame data, and inject arbitrary frames into active spacecraft links.
References (5)
Core 5
Core References
Issue Tracking issue-tracking
Changelog
https://github.com/NASA-AMMOS/AIT-DSN/blob/master/CHANGELOG.md#222---2026-07-13
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-gj83-67wr-82mv)
https://github.com/NASA-AMMOS/AIT-DSN/security/advisories/GHSA-gj83-67wr-82mv
Patch patch
Patch Commit
https://github.com/NASA-AMMOS/AIT-DSN/commit/06d07d1a525602c62c6eaeaeff2544196f430340
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/ait-dsn-missing-authentication-via-sle-api-routes
Scores
CVSS v3
9.8
EPSS
0.0041
EPSS Percentile
33.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-306
Status
published
Products (1)
NASA-AMMOS/AIT-DSN
< 2.2.2
Published
Jul 29, 2026
Tracked Since
Jul 29, 2026