CVE-2026-60113

NASA-AMMOS · AIT-DSN

A missing authentication vulnerability in the NASA-AMMOS AIT-DSN Space Link Extension interface allows unauthenticated remote attackers to execute arbitrary API commands.

Executive summary

The NASA-AMMOS AIT-DSN toolkit contains a critical authentication bypass vulnerability that allows unauthenticated network attackers to control spacecraft communication sessions.

Vulnerability

This vulnerability involves a lack of authentication checks within the Space Link Extension interface manager. An unauthenticated attacker can send direct HTTP requests to seven unprotected API routes, granting them the ability to manipulate DSN sessions and inject telemetry data.

Business impact

Successful exploitation poses a severe risk to mission integrity and operational control. By manipulating Deep Space Network communication sessions or injecting arbitrary frames, an attacker could disrupt critical telemetry data or potentially influence spacecraft operations. Given the CVSS score of 9.8, this vulnerability represents a critical threat that could lead to complete loss of command authority over affected communication links.

Remediation

Immediate Action: Upgrade to NASA-AMMOS AIT-DSN version 2.2.2 or later immediately to implement mandatory authentication for all API endpoints.

Proactive Monitoring: Review access logs for unusual HTTP traffic directed toward the Space Link Extension API routes, specifically looking for unauthorized session creation or termination requests.

Compensating Controls: Deploy a Web Application Firewall or network access control list to restrict access to the AIT-DSN interface to known, authorized IP addresses only.

Exploitation status

Public Exploit Available: No (unknown)

Analyst recommendation

This vulnerability presents a high-risk scenario for any organization utilizing the AIT-DSN toolkit. Administrators must prioritize updating to version 2.2.2 to ensure that critical API routes are properly protected against unauthorized access. Failure to patch allows any network-adjacent actor to interfere with sensitive spacecraft communication protocols.