• NASA's worrying software security flaw

    From Mike Powell@954:895/54 to All on Fri Aug 21 09:38:30 2026
    NASA's ground control software has a worrying security flaw which could let hackers contact spacecraft

    Date:
    Thu, 20 Aug 2026 20:25:00 +0000

    Description:
    Security researchers uncover flaw in the open source software used by NASA ground control to communicate with instruments and spacecraft.

    FULL STORY
    NASAs open source ground control software has a critical vulnerability that could enable an unauthenticated attacker to gain access and take control of spacecraft. The AMMOS Instrument Toolkits browser-based interface is the source of the vulnerability, which has since been resolved.

    The AIT-GUI (AMMOS Instrument Toolkit Graphical User Interface) tool up to version 2.5.1 has been identified as vulnerable, but the fault has been fixed in v2.5.2, according to researcher Yuval Elbar. If the vulnerability had been found by a third party, it would have given access to issue commands to spacecraft, instruments, and execute server-side scripts. In addition,
    command sequences could potentially have been run by an attacker, leaving craft almost wholly beyond NASAs control. Elbar, who works with the Cycode Agentic Development Security Platform, disclosed the vulnerability on August 18, 2026. The problem appears to start with AIT-GUI running as a web server with all network interfaces open, rather than the hosts setting. Incredibly, the API also has no authentication, or authorization protection. In addition, the CSRF (cross-site request forgery) protection on changing endpoints is also absent on affected versions of AIT-GUI.

    Attackers can exploit basic access-control security failings in AIT-GUI, exposing the /cmd and /script/run and /seq prompts while also setting up filesystem paths. This enables files (potentially malware, or custom-built scripts) to be passed directly to NASA craft via a vulnerable AIT-GUI browser session, potentially escalating to full control.

    To emphasize the scale of the weakness, Elbar introduced the disclosure with
    A web GUI used to drive spacecraft and instrument commanding shipped a server that listens on every network interface, asks nobody for a password, and can be steered by any web page an operator happens to open. External access As if this wasnt concerning enough, the attacker doesnt need to be on the same network. Direct access via an exposed port, or directing an operator to a web page hiding malicious code, or even simply a web page under live control by
    an attacker, can afford access to a third party.

    Elbar adds operational and ground-system software inherits the same web weaknesses as everything else, but with a far higher cost of failure. Auth, CSRF defense, and input confinement are not optional extras on a panel that commands hardware.

    Cycode advises administrators of AIT systems to upgrade AIT-GUI to v2.5.2 and run checks on the console port. They should also review command history.

    Link to news story: https://www.techradar.com/pro/security/nasas-ground-control-software-has-a-wor rying-security-flaw-which-could-let-hackers-contact-spacecraft

    $$
    --- MultiMail/DOS
    * Origin: capitolcityonline.net * KY, USA (954:895/54)