Remote Code Execution in NASA RtRetrieval Framework
CVE-2018-1000048

8.8HIGH

Key Information:

Vendor

Nasa

Vendor
CVE Published:
9 February 2018

What is CVE-2018-1000048?

The NASA RtRetrievalFramework version v1.0 has a vulnerability in its data retrieval functionality that allows an attacker to exploit the system by sending crafted weather data files. This can potentially lead to remote code execution, giving malicious actors unauthorized access and control over the affected system. Users of this framework should take precautionary measures to secure their applications and prevent unauthorized data retrieval.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2018-1000048 : Remote Code Execution in NASA RtRetrieval Framework