NASA AIT-GUI의 보안 취약점으로 인해 인증되지 않은 공격자가 우주선 명령을 발행할 수 있다.
Cycode의 보안 연구원들이 NASA/JPL의 AIT-GUI에서 발견한 취약점 체인을 공개했다. 이 취약점은 인증되지 않은 공격자가 소프트웨어의 우주선 및 기기 명령 버스에 임의의 명령을 발행할 수 있게 한다. 해당 취약점은 CVSS v3.1에서 9.4로 평가되며, AIT-GUI에 영향을 미친다.
NASA's AIT-GUI vulnerabilities allow unauthenticated attackers to issue commands to spacecraft.
Security researchers at Cycode have disclosed vulnerabilities in NASA/JPL's AIT-GUI, which allow unauthenticated attackers to send arbitrary commands to the spacecraft and instrument command bus. This vulnerability chain has been rated 9.4 on the CVSS v3.1 scoring system and poses significant risks to the AIT-GUI software.