CVE-2025-25371 Details
Description
NASA cFS (Core Flight System) Aquila is vulnerable to path traversal in the OSAL module, allowing the override of any arbitrary file on the system.
A path traversal vulnerability has been identified in the OSAL module of NASA's Core Flight System (cFS) version Aquila. This vulnerability allows attackers to write files outside of designated directories, potentially overwriting critical system files. The issue arises from improper validation of file paths, enabling the manipulation of file locations based on the application's virtual mount point.
It is recommended to implement proper path validation that converts user-inputted file paths into absolute paths before verification. Additionally, restricting write access to sensitive files can prevent potential corruption.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 26, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://visionspace.com/nasa-cfs-version-aquila-software-vulnerability-assessment/ | CISA-ADP | ExploitThird Party Advisory |
| https://visionspace.com/nasa-cfs-version-aquila-software-vulnerability-assessment/ | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| nasa core flight system | 6.7.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 30, 2026 | Modified Analysis | [email protected] |
| Apr 3, 2025 | Initial Analysis | [email protected] |
| Mar 26, 2025 | CVE Modified | CISA-ADP |
| Mar 25, 2025 | New CVE Received | [email protected] |