Junglewise Threat Intelligence

CVE-2024-43795: PYSEC-2024-100 - OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. The login functional

CVE-2024-43795 · Severity: low · CVSS 3.1 · Published 2024-10-02

Technologies: openc3 (RubyGems), openc3 (PyPI), Openc3 Cosmos. Vendors: RubyGems, npm, PyPI, Openc3.

Executive brief

OpenC3 COSMOS is an open-source mission control and operations software platform used to manage complex systems and satellite operations. A reflected cross-site scripting vulnerability in the login functionality allows attackers to inject malicious scripts that execute in users' browsers, potentially leading to session hijacking, credential theft, or further compromise of the operations environment.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in OpenC3 COSMOS's login functionality, classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). The vulnerability stems from insufficient input sanitization before rendering user-controllable data in the login page. The attack is network-accessible and requires user interaction (a victim must click a crafted link), with no authentication prerequisites. An attacker can craft a malicious URL containing JavaScript payload that executes in the victim's browser within the COSMOS application context, potentially enabling session hijacking, credential harvesting, or RCE through further exploitation. The fix is available in version 5.19.0 and later. This vulnerability affects the Open Source Edition only, not the Enterprise Edition.

Affected products

  • OpenC3 COSMOS before 5.19.0

Timeline

  • 2024-10-02: disclosed
  • 2024-10-02: patched: Version 5.19.0 released

References

Related threats