Executive brief
The AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) interface is used to manage communications between ground stations and spacecraft. A security flaw allows unauthorized individuals to bypass authentication and access critical control functions. In practice, an attacker could disrupt space missions by starting or stopping communication sessions, stealing telemetry data, or injecting unauthorized commands directly into active spacecraft links.
Technical details
A missing authentication vulnerability exists in the Space Link Extension (SLE) interface manager of AIT-DSN before version 2.2.2. The vulnerability stems from two primary issues: first, the CLTU UDP listener incorrectly binds to the IPv6 wildcard address (::) instead of the configured host, exposing the service to the network; second, the SLE interface manager lacks authentication checks on seven critical API routes. An unauthenticated network attacker can send direct HTTP and UDP requests to start/stop DSN sessions, retrieve telemetry, or append arbitrary bytes to the Command Link Transmission Unit (CLTU) upload queue. These injected bytes are subsequently wrapped into SLE PDUs and transmitted to the spacecraft. The issue is resolved in version 2.2.2 by enforcing loopback binding and adding state-based authentication checks.
Affected products
- NASA-AMMOS AIT-DSN < 2.2.2
Timeline
- 2026-07-13: patched: Fixes committed in version 2.2.2
- 2026-07-29: disclosed: CVE-2026-60113 published
References
- https://github.com/NASA-AMMOS/AIT-DSN/blob/master/CHANGELOG.md
- https://github.com/NASA-AMMOS/AIT-DSN/commit/06d07d1a525602c62c6eaeaeff2544196f430340
- https://github.com/NASA-AMMOS/AIT-DSN/releases/tag/2.2.2
- https://github.com/NASA-AMMOS/AIT-DSN/security/advisories/GHSA-gj83-67wr-82mv
- https://www.vulncheck.com/advisories/ait-dsn-missing-authentication-via-sle-api-routes