CVE-2026-105105
Received Received - Intake

Missing Authentication in AIT-Core ZeroMQ Broker

Vulnerability report for CVE-2026-105105, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: TuranSec

Description

CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message bus to inject spacecraft command data, exfiltrate command and telemetry traffic, inject forged telemetry, or disrupt the command and telemetry bus. The ait-server ZeroMQ broker binds its XSUB and XPUB sockets to all network interfaces by default without authentication or transport security. An attacker able to reach TCP port 5559 can publish messages onto internal topics, including the __commands__ command topic. With the shipped default configuration, command messages are forwarded through command_stream and emitted on the command-uplink UDP path. An attacker able to reach TCP port 5560 can subscribe to command and telemetry traffic on the ground bus. AIT-Core 3.1.2 changes the default ZeroMQ bind addresses to loopback.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
nasa ait-core to 3.1.1 (inc)
nasa ait-core 3.1.1
nasa ait-core 3.1.2
nasa ait-core_gui to 2.5.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105105 is a critical missing authentication vulnerability in NASA's AIT-Core ait-server component. It allows unauthenticated remote attackers to inject spacecraft commands, exfiltrate telemetry data, forge telemetry, or disrupt the command and telemetry bus. The flaw exists because the ait-server binds its ZeroMQ message bus to all network interfaces without authentication or transport security on ports 5559 and 5560. Attackers can publish commands to the spacecraft uplink or subscribe to real-time telemetry traffic.

Detection Guidance

Check if ait-server is binding to all network interfaces on ports 5559 or 5560 using netstat or ss commands. For example: netstat -tulnp | grep -E '5559|5560' or ss -tulnp | grep -E '5559|5560'. If these ports are exposed externally, the system is vulnerable.

Impact Analysis

This vulnerability allows attackers to inject arbitrary spacecraft commands, potentially causing unauthorized operations or system disruptions. They can also exfiltrate sensitive command and telemetry data, forge telemetry to manipulate operator displays, or disrupt the command and telemetry bus, leading to loss of control or misinformation. The impact includes compromised confidentiality, integrity, and availability of spacecraft operations.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and system integrity. GDPR requires protection of personal data, which could be compromised if telemetry includes such data. HIPAA mandates secure handling of health-related information, which may be exposed or manipulated. The lack of authentication and transport security violates security best practices required by these regulations.

Mitigation Strategies

Upgrade AIT-Core to version 3.1.2 or later, which restricts the ZeroMQ bus to the loopback interface by default. If upgrading is not possible, configure the ZeroMQ broker to bind only to 127.0.0.1 or implement ZeroMQ CURVE authentication or mutual TLS for multi-host deployments.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105105. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart