Missing Authentication Vulnerability in NASA's AIT-Core Product
CVE-2026-105105

9.8CRITICAL

Key Information:

Vendor

Nasa-ammos

Status
Vendor
CVE Published:
3 October 2026

What is CVE-2026-105105?

The AIT-Core telemetry and command broker (ait-server) is susceptible to a vulnerability that allows unauthenticated remote access to its ZeroMQ message bus. This issue arises because the broker binds its XSUB and XPUB sockets to all network interfaces by default, exposing it to potential attacks. An unauthenticated attacker with network access can intercept command and telemetry traffic, inject malicious spacecraft command data, or disrupt communications that are critical for operations. Specifically, access to TCP ports 5559 and 5560 enables command message publishing and subscription to sensitive traffic on the ground bus. AIT-Core version 3.1.2 addresses these security concerns by changing the default binding addresses to enhance protection.

Affected Version(s)

AIT-Core 0 <= 3.1.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shukrulloh Raximov (Mothra)
.