CVE-2026-60113
AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network attackers to access seven unprotected API routes by sending direct HTTP requests with no credentials. Attackers can reach the exposed SLE endpoints to start or stop Deep Space Network communication sessions, retrieve telemetry frame data, and inject arbitrary frames into active spacecraft links.
Published:Jul 29, 2026
Last Modified:Aug 18, 2026
EPS:Jul 29, 2026
EPSS Score:0.00408
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Nasa
Product
Ait Dsn
Nasa
Ait Dsn
Vendor
Nasa-ammos
Product
Ait-dsn
Nasa-ammos
Ait-dsn
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
