Post

NASA Core Flight System Health & Safety Application Vulnerability Advisory

NASA Core Flight System Health & Safety Application Vulnerability Advisory

NASA Core Flight System (cFS) Health & Safety (HS) Application Vulnerability Advisory

🚨 Attention! A critical vulnerability has been identified in the NASA Core Flight System (cFS) Health & Safety (HS) Application. Successful exploitation could allow an attacker to cause a denial-of-service condition. The affected versions are cFS Health & Safety Application <= v7.0.1 (CVE-2026-18064). This vulnerability impacts Critical Infrastructure Sectors, specifically Transportation Systems, and is deployed worldwide.

Details of the Vulnerability

An incomplete fix for CVE-2026-15352 leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause the HS application to crash, resulting in a denial-of-service condition and processor reset. The relevant CWE is CWE-476 NULL Pointer Dereference.

Michael Holmquist of Hasp Labs reported this vulnerability to CISA. Currently, no known public exploitation specifically targeting this vulnerability has been reported.

Mitigation Measures

NASA reports that an official fix is under development and is expected to be included in a future software release. As an interim measure, users can update their HS app from the HS repository here to the latest dev branch, starting at commit 828855f971db4b6714367ed0a970f52dbeab2965.

CISA recommends taking defensive measures to minimize the risk of exploitation. These include:

  • Minimizing network exposure for all control system devices.
  • Ensuring they are not accessible from the internet.
  • Locating control system networks and remote devices behind firewalls.
  • Using secure methods for remote access, such as Virtual Private Networks (VPNs).

For more detailed recommendations, organizations should perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage.

Conclusion

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

Read full article

This post is licensed under CC BY 4.0 by the author.