CVE-2026-67969

NASA · cFS

A vulnerability in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows unauthenticated attackers to trigger a processor reset using a crafted HS.AppMon_Tbl entry.

Executive summary

This vulnerability is confirmed to be actively exploited in the wild and allows remote attackers to force a processor reset in NASA cFS v7.0.1.

Vulnerability

The HS_MonitorApplications() component fails to properly validate the HS.AppMon_Tbl entry, allowing an unauthenticated attacker to supply a crafted input that forces the processor to reset. This represents a significant failure in health monitoring logic within the flight software framework.

Business impact

With a CVSS score of 7.5, this high-severity flaw directly impacts the operational integrity of the system. Because it is confirmed to be under active exploitation, the risk of unauthorized system resets, leading to service outages and potential mission failure, is immediate and severe.

Remediation

Immediate Action: Monitor the vendor advisory at https://github.com/nasa/cFS/issues/1069 for the release of a patch and apply it immediately upon availability.

Proactive Monitoring: Closely monitor system health logs for unauthorized or unexpected processor reset events and scrutinize any modifications to the HS.AppMon_Tbl entries.

Compensating Controls: Utilize hardware-level watchdogs or secondary monitoring systems to detect and recover from unauthorized processor resets caused by external input.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The active exploitation of this vulnerability necessitates immediate attention. Security teams must treat this as a top-priority issue and implement all available mitigations while awaiting a formal software update from the vendor.

More NASA CVEs