NASA Core Flight System (cFS) Health & Safety (HS) Application
MonitorCVSS 7.5ICS-CERT ICSA-26-211-06Jul 30, 2026
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
A null pointer dereference vulnerability in the NASA Core Flight System (cFS) Health & Safety (HS) Application v7.0.1 and earlier allows an attacker with network access to cause a denial-of-service condition by sending crafted packets that crash the HS application. The HS application does not properly validate input, resulting in improper exception handling. Successful exploitation could disrupt health monitoring and anomaly detection for spacecraft and satellite systems.
What this means
What could happen
An attacker with network access to the Core Flight System could send crafted packets that crash the Health & Safety application, disrupting monitoring and control functions for spacecraft or satellite systems that depend on HS for health checks and anomaly detection.
Who's at risk
Satellite operations, spacecraft command and control systems, and any aerospace or space agency missions that rely on NASA's Core Flight System for real-time health monitoring and diagnostic functions. This includes ground control stations and onboard flight computers running the cFS HS application.
How it could be exploited
An attacker on the network sends a malformed packet to the HS application that triggers a null pointer dereference in the application logic. The application crashes without proper input validation, causing a denial-of-service condition and loss of real-time health monitoring capabilities.
Prerequisites
- Network access to the Core Flight System running cFS HS application v7.0.1 or earlier
- No authentication required to send packets to the HS application
remotely exploitableno authentication requiredlow complexityaffects safety systemsno patch available (mitigation only)
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (1)
ProductAffected VersionsFix Status
Core Flight System (cFS) Health & Safety (HS) Application≤ v7.0.1No fix yet
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate the HS application from the official GitHub repository (https://github.com/nasa/HS) to the dev branch at or after commit 828855f971db4b6714367ed0a970f52dbeab2965
Long-term hardening
0/2HARDENINGImplement network segmentation to restrict access to the Core Flight System to only authorized management and telemetry interfaces
HARDENINGMonitor for unusual packet patterns or connection attempts to the HS application and log all access for auditing
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/81720bab-bcfd-4af8-8672-8c300d65848cGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.