CVE-2026-67973

7.5

NASA · cFS

A flaw in the CFDP receive path of NASA cFS v7.0.1 allows unauthenticated attackers to cause a Denial of Service through the replay of final CFDP PDUs.

Executive summary

A critical denial of service vulnerability in NASA cFS v7.0.1 allows remote, unauthenticated attackers to disrupt system availability by replaying protocol data units.

Vulnerability

This vulnerability exists within the CFDP receive path where the software fails to properly handle replayed final CFDP PDUs. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) confirms that this is an unauthenticated, network-accessible flaw that requires no user interaction to trigger.

Business impact

Successful exploitation of this vulnerability results in a Denial of Service, which can cause significant operational disruption for systems utilizing the cFS framework. Given the CVSS score of 7.5, the risk is classified as High, as it directly threatens the availability of mission-critical communication processes. Organizations relying on this software for data transmission may face total service interruption if an attacker targets the receive path.

Remediation

Immediate Action: Monitor the official NASA cFS GitHub repository for the release of a security patch addressing this issue and apply it immediately upon availability.

Proactive Monitoring: Implement network traffic monitoring to identify anomalous CFDP PDU patterns or repeated transmission attempts that may indicate a replay attack in progress.

Compensating Controls: Deploy network-level traffic filtering or protocol-specific inspection to drop malformed or suspicious CFDP packets before they reach the cFS receive path.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The vulnerability presents a clear risk to service availability through remote, unauthenticated exploitation. While a specific patch is currently pending, administrators must prioritize the monitoring of cFS communication channels for signs of replay-based disruption. Apply the vendor-provided update as soon as it is released to eliminate the underlying flaw.

More NASA CVEs

Sources