NASA Core Flight System (cFS) Health & Safety (HS) Application
NASA has issued an advisory regarding a vulnerability in its Core Flight System (cFS) Health & Safety (HS) Application, potentially leading to denial-of-service conditions. The vulnerability, identified as a segmentation fault, affects version v7.0.1 and requires updating to v7.0.1 to mitigate the risk. NASA recommends implementing defensive measures such as minimizing network exposure and isolating control systems.
NASA has issued an advisory regarding a vulnerability in its Core Flight System (cFS) Health & Safety (HS) Application. The flaw allows the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request, leading to denial of service. The affected product is NASA Core Flight System (cFS) Health & Safety (HS) Application, version v7.0.1. This vulnerability is classified as a segmentation fault. The advisory recommends users update to v7.0.1 to mitigate the risk. NASA recommends implementing defensive measures such as minimizing network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Additionally, control system networks and remote devices should be located behind firewalls and isolated from business networks. Secure remote access methods, like VPNs, should be utilized, recognizing that VPNs themselves may have vulnerabilities and should be updated to the most current version available. CISA recommends organizations perform proper impact analysis and risk assessment prior to deploying defensive measures. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.