top of page
perceptive_background_267k.jpg

AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE)…

Published:

28 juli 2026 om 22:00:00

Alert date:

29 juli 2026 om 17:02:28

Source:

nvd.nist.gov

Click to open the original link from this advisory

Critical Infrastructure, Network Infrastructure, Identity & Access, Zero-Day Vulnerabilities

CVE-2026-60113 is a missing authentication vulnerability in the AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface prior to version 2.2.2. The flaw exists in the Space Link Extension (SLE) interface manager, which exposes seven unprotected API routes accessible via direct HTTP requests without any credentials. Unauthenticated network attackers can exploit these endpoints to start or stop Deep Space Network communication sessions, retrieve telemetry frame data, and inject arbitrary frames into active spacecraft links. The vulnerability poses a critical risk to spacecraft operations and deep space mission integrity. A fix was released in version 2.2.2 on 2026-07-13. References include the official GitHub changelog, a specific commit, a release tag, a GitHub Security Advisory (GHSA-gj83-67wr-82mv), and a VulnCheck advisory. The severity is rated High given the potential for direct interference with active spacecraft communications.

Technical details

Mitigation steps:

Affected products:

AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page