External risk intelligence

NASA-AMMOS AIT-Core Broker Unauthorized Command Injection and Data Exfiltration

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-105105

The vulnerability affects a telemetry and command broker for spacecraft systems. While the service binds to all interfaces by default, these systems are specialized, typically deployed within isolated internal research or mission operations networks, and are not designed for direct public internet exposure.

Missing Authentication

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This CVE concerns a security flaw in a system used for spacecraft command and telemetry, affecting how commands and data are transmitted. The vulnerability allows unauthenticated attackers with network access to inject commands, steal data, or disrupt communications. While the system's default configuration could be exposed, its specialized nature suggests it's likely used in isolated environments, making broad external exploitation improbable.

  • Allows unauthorized control of critical systems.
  • Protects against data breaches and disruptions.
  • Confirm relevance and exposure for specialized systems.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker with network access to the ZeroMQ message bus can reach the telemetry and command broker. By publishing messages to specific topics, an attacker can inject commands, exfiltrate traffic, or disrupt the bus, potentially leading to unauthorized control or data compromise.

  • Network access to specific ports required.
  • Publish messages to internal topics.
  • Inject commands, exfiltrate data, or disrupt bus.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated remote attacker with network access to the telemetry and command broker to interfere with spacecraft operations. By sending commands to the broker, an attacker could potentially inject new commands, view existing command and telemetry traffic, or insert false telemetry data, thereby disrupting the command and telemetry bus.

  • Spacecraft command and telemetry data.
  • Network access to the message bus.
  • Disruption of spacecraft operations.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the ait-server telemetry and command broker likely impacts NASA's mission operations and ground system teams. The primary first step is to identify all instances of the affected technology, confirm their network reachability and criticality to ongoing operations, and then determine the accountable owner for remediation planning.

  • Identify affected systems and owners.
  • Verify network exposure and criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is NASA-AMMOS AIT-Core?

NASA-AMMOS AIT-Core is a software framework utilized for spacecraft assembly, integration, and testing. Its ait-server component specifically acts as a telemetry and command broker, managing the transmission of critical data and control signals between ground systems and spacecraft hardware.

What does CWE-306 mean for CVE-2026-105105?

CWE-306 is the classification for Missing Authentication for Critical Function. In this specific vulnerability, the ait-server fails to verify the identity of anyone connecting to its message bus. This allows unauthorized parties to treat the broker as an open gateway, enabling them to send commands, read telemetry, or disrupt system communication as if they were legitimate operators.

How can an attacker trigger this vulnerability?

An attacker triggers this flaw by reaching the ZeroMQ message bus on TCP ports 5559 or 5560. Simply accessing the network path is sufficient; no credentials are required. Note that this bug does not trigger if the service is configured to bind only to loopback addresses, as the broker would then reject external network connections.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal notes that while the service binds to all interfaces by default, the risk is classified as unlikely for public internet exposure. Because AIT-Core is designed for specialized spacecraft mission operations, it is typically deployed within isolated, highly protected research networks rather than exposed to the open web.

What should I do if I use AIT-Core?

First, locate all running instances of AIT-Core within your environment to determine their network reachability. Check if your deployment is utilizing default settings that bind to all interfaces. Once identified, consult the updated documentation to move toward more restrictive binding configurations and establish clear ownership for formal security patching.

References