Denial of Service Vulnerability in NASA cFS Software
CVE-2026-67973

7.5HIGH

Key Information:

Vendor

NASA

Status
Vendor
CVE Published:
3 August 2026

What is CVE-2026-67973?

NASA cFS v7.0.1 has a vulnerability in its CFDP receive path that allows attackers to exploit the system by replaying final CFDP Protocol Data Units (PDUs). This could lead to a Denial of Service (DoS), disrupting the normal functioning of the software and potentially impacting critical operations. Organizations using this version should review their security practices and consider implementing safeguards to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.