Buffer Overflow Vulnerability in NASA cFS SBN TCP Module
CVE-2026-82479
5.3MEDIUM
What is CVE-2026-82479?
A vulnerability was discovered in the NASA cFS system related to the SBN TCP Module, specifically within the OS_read function located in the sbn_tcp_if.c file. This issue arises from improper handling of the MsgSz argument, which could allow a malicious actor on the local network to manipulate this argument, leading to a buffer overflow condition. Consequently, this could enable unauthorized access or control over the affected system. Despite early notifications to the vendor regarding this vulnerability, no response was received.
Affected Version(s)
cFS 7.0.0
cFS 7.0.1
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
juntheworld (VulDB User)
VulDB CNA Team
