CVE-2026-60113 Details
Description
AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network attackers to access seven unprotected API routes by sending direct HTTP requests with no credentials. Attackers can reach the exposed SLE endpoints to start or stop Deep Space Network communication sessions, retrieve telemetry frame data, and inject arbitrary frames into active spacecraft links.
A missing authentication vulnerability has been identified in the NASA AMMOS AIT Deep Space Network (DSN) Interface, specifically in versions prior to 2.2.2. The vulnerability resides within the Space Link Extension (SLE) interface manager, where unauthenticated network attackers can access seven unprotected API routes. By sending direct HTTP requests without credentials, attackers can manipulate Deep Space Network communication sessions, retrieve telemetry frame data, and inject arbitrary frames into active spacecraft links.
Users can update to AIT-DSN version 2.2.2, which addresses the vulnerability by adding authentication for the SLE upload_CLTU function and restricting the CLTU UDP listener to loopback-only.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/NASA-AMMOS/AIT-DSN/security/advisories/GHSA-gj83-67wr-82mv | CISA-ADP | ExploitVendor Advisory |
| https://github.com/NASA-AMMOS/AIT-DSN/blob/master/CHANGELOG.md#222---2026-07-13 | [email protected] | Release Notes |
| https://github.com/NASA-AMMOS/AIT-DSN/commit/06d07d1a525602c62c6eaeaeff2544196f430340 | [email protected] | Patch |
| https://github.com/NASA-AMMOS/AIT-DSN/releases/tag/2.2.2 | [email protected] | ProductRelease Notes |
| https://github.com/NASA-AMMOS/AIT-DSN/security/advisories/GHSA-gj83-67wr-82mv | [email protected] | ExploitVendor Advisory |
| https://www.vulncheck.com/advisories/ait-dsn-missing-authentication-via-sle-api-routes | [email protected] | PatchRelease NotesThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nasa ait dsn | < 2.2.2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 18, 2026 | Initial Analysis | [email protected] |
| Jul 30, 2026 | CVE Modified | CISA-ADP |
| Jul 29, 2026 | New CVE Received | [email protected] |