NASA Core Flight System (cFS) Health & Safety (HS) Application

MonitorCVSS 7.5ICS-CERT ICSA-26-197-03Jul 16, 2026
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

A null pointer dereference vulnerability in NASA's Core Flight System (cFS) Health & Safety (HS) Application versions prior to 7.0.1 allows an attacker to cause a denial-of-service condition by crashing the health and safety monitoring application. The vulnerability requires only network access and no credentials.

What this means
What could happen
An attacker could crash or disable the Core Flight System Health & Safety application, interrupting health monitoring and safety checks on spacecraft or ground-based mission-critical systems.
Who's at risk
Operators of NASA spacecraft, ground stations, and mission-critical systems using the Core Flight System Health & Safety (HS) application in versions prior to 7.0.1. This affects organizations running cFS-based health monitoring and safety systems for space missions or related applications.
How it could be exploited
An attacker with network access to the cFS HS application could send a specially crafted message or input that triggers a null pointer dereference (CWE-476), causing the application to crash and stop processing health and safety monitoring functions.
Prerequisites
  • Network access to the cFS HS application port
  • No authentication required
remotely exploitableno authentication requiredlow complexityaffects safety systems
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (1)
ProductAffected VersionsFix Status
Core Flight System (cFS) Health & Safety (HS) Application<v7.0.1No fix yet
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate cFS Health & Safety Application to version 7.0.1 or later
API: /api/v1/advisories/4fd107e9-efb1-4f89-9739-021da895ecf2

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.