Sceawere

Vulnerability Detail

CVE-2026-105105UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

AIT-Core Unauthenticated ZeroMQ Access

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
NASA-AMMOS
Product
AIT-Core
Attack Type
CWE-306: Missing Authentication for Critical Function
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message bus to inject spacecraft command data, exfiltrate command and telemetry traffic, inject forged telemetry, or disrupt the command and telemetry bus. The ait-server ZeroMQ broker binds its XSUB and XPUB sockets to all network interfaces by default without authentication or transport security. An attacker able to reach TCP port 5559 can publish messages onto internal topics, including the __commands__ command topic. With the shipped default configuration, command messages are forwarded through command_stream and emitted on the command-uplink UDP path. An attacker able to reach TCP port 5560 can subscribe to command and telemetry traffic on the ground bus. AIT-Core 3.1.2 changes the default ZeroMQ bind addresses to loopback.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-03T12:16:57.183Z",
  "pubdate": "2026-10-03T12:16:57.183Z",
  "executiveSummary": "The NASA-AMMOS AIT-Core ait-server is susceptible to CWE-306: Missing Authentication for Critical Function due to a lack of security controls on its ZeroMQ message bus.\nThe vulnerability resides in the telemetry and command broker, which exposes XSUB and XPUB sockets across all network interfaces by default without implementing authentication or transport layer security.\nAn unauthenticated remote attacker with network access to the broker on TCP ports 5559 or 5560 can perform unauthorized actions, including the injection of malicious spacecraft commands, interception of sensitive telemetry and command traffic, and disruption of the message bus.\nThis represents a significant security risk, as the integrity and confidentiality of command-and-control operations for spacecraft systems are compromised.\nExploitation is trivial for any actor within the network perimeter, requiring no prior authentication or specialized privileges.\nThe issue affects AIT-Core through version 3.1.1, with version 3.1.2 providing a partial mitigation by restricting default bind addresses to the loopback interface.",
  "technicalDetails": "The root cause of this vulnerability is the absence of an authentication mechanism and transport layer security (TLS) for the ZeroMQ message broker implemented within the ait.core.server. By default, the ait-server binds its XSUB and XPUB sockets to all available network interfaces (0.0.0.0), effectively exposing the command-and-control bus to any host with TCP connectivity to the service.\nThe ZeroMQ broker utilizes TCP port 5559 for upstream/command injection and TCP port 5560 for downstream telemetry/command subscription. Because the system lacks an identity verification layer, the ZeroMQ sockets accept connections from any remote entity without enforcing security policies.\nThe attack flow proceeds as follows: First, an attacker performs network reconnaissance to identify the ait-server instance by probing for open ports 5559 or 5560. Second, upon establishing a TCP connection to port 5559, the attacker can transmit arbitrary messages directly into the internal message bus. By targeting the '__commands__' topic, an attacker can inject spacecraft command data. Because the default configuration routes these command messages through the command_stream and onto the command-uplink UDP path, the injected commands are forwarded to the target hardware, resulting in unauthorized command execution.\nThird, by connecting to port 5560, an attacker can subscribe to all published messages on the ground bus. This allows for the exfiltration of sensitive telemetry and command traffic, violating data confidentiality. Furthermore, an attacker may inject forged telemetry data, potentially leading to incorrect situational awareness or system state misinterpretation by the telemetry monitoring components.\nThe impact of this vulnerability is critical, as it provides a mechanism for remote code execution context if command injection allows for unauthorized device manipulation, as well as a complete loss of confidentiality and integrity regarding spacecraft operations.\nAffected versions include all releases up to and including AIT-Core 3.1.1. While AIT-Core 3.1.2 mitigates the exposure by defaulting bind addresses to the loopback interface, this does not address the underlying lack of authentication if the service is explicitly reconfigured to listen on external interfaces."
}
CVE-2026-105105: AIT-Core Unauthenticated ZeroMQ Access (CRITICAL Severity, CVSS: 9.8) | Sceawere