CVE-2026-60113
Received Received - Intake

Unauthenticated API Access in AMMOS Instrument Toolkit DSN Interface

Vulnerability report for CVE-2026-60113, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-29

Last updated on: 2026-07-29

Assigner: VulnCheck

Description

AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network attackers to access seven unprotected API routes by sending direct HTTP requests with no credentials. Attackers can reach the exposed SLE endpoints to start or stop Deep Space Network communication sessions, retrieve telemetry frame data, and inject arbitrary frames into active spacecraft links.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-29
Last Modified
2026-07-29
Generated
2026-07-30
AI Q&A
2026-07-30
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-60113 is a missing authentication vulnerability in AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before version 2.2.2. It exposes seven API routes in the Space Link Extension (SLE) interface manager that do not require authentication. Attackers can send direct HTTP requests to these endpoints to control DSN communication sessions, access telemetry data, or inject arbitrary frames into spacecraft links.

Detection Guidance

Check for unauthenticated HTTP requests to the SLE interface manager endpoints. Monitor network traffic for direct HTTP requests to the exposed API routes. Verify if AIT DSN Interface versions before 2.2.2 are installed on your system.

Impact Analysis

This vulnerability allows unauthenticated attackers to manipulate Deep Space Network operations. They could disrupt communications with spacecraft, steal sensitive telemetry data, or send unauthorized commands to active links. The high CVSS scores (9.3 v4.0, 9.8 v3.1) indicate severe impact potential, including complete system compromise.

Mitigation Strategies

Upgrade AIT DSN Interface to version 2.2.2 or later. Implement authentication for the SLE interface manager API routes. Restrict network access to the SLE endpoints using firewalls or network segmentation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-60113. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart