CyberRota Analysis
AI-GeneratedA buffer overflow vulnerability exists in the OS_read function of the SBN TCP Module in NASA's cFS versions up to 7.0.1, which can be exploited by an attacker within the local network by manipulating the MsgSz argument. This could potentially lead to unauthorized access or execution of arbitrary code. Organizations using affected versions of NASA's cFS should prioritize remediation to mitigate the risk of local network attacks.
Original NVD Description
A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the component SBN TCP Module. Such manipulation of the argument MsgSz leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any way.