CVE-2026-60113 PUBLISHED

AIT-DSN < 2.2.2 Missing Authentication via SLE API Routes

Assigner: VulnCheck
Reserved: 08.07.2026 Published: 29.07.2026 Updated: 30.07.2026

AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network attackers to access seven unprotected API routes by sending direct HTTP requests with no credentials. Attackers can reach the exposed SLE endpoints to start or stop Deep Space Network communication sessions, retrieve telemetry frame data, and inject arbitrary frames into active spacecraft links.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor NASA-AMMOS
Product AIT-DSN
Versions Default: affected
  • affected from 0 to 2.2.2 (excl.)

Credits

  • Saidakbarxon Maxsudxonov finder
  • VulnCheck coordinator

References

Problem Types

  • Missing Authentication for Critical Function CWE