CVE-2026-67976

NASA · fprime

The Ref::SignalGen component in the fprime framework version 4.2.2 fails to validate user-controlled parameters, which enables unauthenticated attackers to trigger a Denial of Service.

Executive summary

A high-severity Denial of Service vulnerability in the NASA fprime framework allows unauthenticated attackers to disrupt system availability.

Vulnerability

The vulnerability resides in the Ref::SignalGen component and stems from a lack of input validation on user-supplied parameters. As indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:N), this flaw is reachable by an unauthenticated attacker over the network.

Business impact

The ability for an unauthenticated actor to trigger a Denial of Service presents a significant operational risk, particularly given the framework's use in embedded and flight software environments. With a CVSS score of 7.5, the vulnerability is classified as High, reflecting the potential for significant service disruption and loss of system availability.

Remediation

Immediate Action: Monitor the official NASA fprime GitHub repository for the release of an official patch or security guidance addressing the Ref::SignalGen component.

Proactive Monitoring: Review application and system access logs for anomalous input patterns or unexpected service restarts that may indicate exploitation attempts.

Compensating Controls: Implement strict network ingress filtering to restrict access to the fprime framework to authorized personnel and trusted systems only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for service disruption in high-stakes environments, organizations utilizing fprime version 4.2.2 should prioritize the identification of exposed instances and restrict network access immediately. While an official patch is pending, rigorous monitoring of system stability and network traffic is essential to detect and block potential exploitation attempts.

More NASA CVEs

Sources