CyberRota Analysis
AI-GeneratedThe AMMOS Instrument Toolkit (AIT) GUI prior to version 2.5.1 is vulnerable due to a missing authentication mechanism, enabling unauthenticated network attackers to create valid sessions and issue arbitrary commands to spacecraft systems. This critical vulnerability allows attackers to bypass authentication entirely, posing severe risks to the integrity and security of spacecraft operations. Organizations utilizing AIT should prioritize immediate updates to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() without any credential check. Attackers can exploit the unauthenticated session issuance in Sessions.create() and subsequently invoke handle_cmd() to forward arbitrary commands directly to the AIT command bus without any authentication gate between session creation and command dispatch.
Related CVEs
Other vulnerabilities affecting the same vendor(s)