CVE-2026-60113

Source
https://cve.org/CVERecord?id=CVE-2026-60113
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-60113.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-60113
Aliases
  • GHSA-gj83-67wr-82mv
Published
2026-07-29T15:40:26.747Z
Modified
2026-08-20T03:54:33.471548567Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
AIT-DSN < 2.2.2 Missing Authentication via SLE API Routes
Details

AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network attackers to access seven unprotected API routes by sending direct HTTP requests with no credentials. Attackers can reach the exposed SLE endpoints to start or stop Deep Space Network communication sessions, retrieve telemetry frame data, and inject arbitrary frames into active spacecraft links.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-306"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/60xxx/CVE-2026-60113.json"
}
References

Affected packages

Git / github.com/nasa-ammos/ait-dsn

Affected ranges

Type
GIT
Repo
https://github.com/nasa-ammos/ait-dsn
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.2.2"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "cpe": "cpe:2.3:a:nasa:ait_dsn:*:*:*:*:*:*:*:*"
}

Affected versions

1.*
1.0.0
1.1.0
2.*
2.0.0
2.0.1-rc1
2.1.1-rc1
2.2.0
2.2.1
Other
encrypt_init_rel
encrypt_update1_rel

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-60113.json"