CVE-2026-60113

CRITICAL

NASA-AMMOS AIT-DSN < 2.2.2 - Missing Authentication in SLE API Routes

Title source: manual
STIX 2.1

Description

AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network attackers to access seven unprotected API routes by sending direct HTTP requests with no credentials. Attackers can reach the exposed SLE endpoints to start or stop Deep Space Network communication sessions, retrieve telemetry frame data, and inject arbitrary frames into active spacecraft links.

Scores

CVSS v3 9.8
EPSS 0.0041
EPSS Percentile 33.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-306
Status published
Products (1)
NASA-AMMOS/AIT-DSN < 2.2.2
Published Jul 29, 2026
Tracked Since Jul 29, 2026