CyberRota Analysis
AI-GeneratedNASA cFS v7.0.1 is vulnerable due to incorrect access control, enabling attackers to manipulate subscription management by removing low-index subscriptions and adding new streams through TO_LAB commands. This could lead to unauthorized data access or disruption of service. Organizations using this version of cFS should prioritize remediation to mitigate potential exploitation risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands.