synced 9 MIN AGO
01 Record

CVE-2026-105105

Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft command injection and telemetry exfiltration

CriticalPUBLISHEDCNA: TuranSec
CNA base score9.8 CVSS v3.xCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

02 Description

Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft command injection and telemetry exfiltration

03 Exploitation and scoring

Exploitation
Assessed, none found. CISA's assessment recorded neither public exploit code nor evidence of exploitation when it was made.
SSVC decision
  • ExploitationnoneCISA recorded no public exploit code and no evidence of exploitation.
  • AutomatableyesAn attacker can reliably automate reconnaissance through exploitation, so this scales.
  • Technical ImpacttotalSuccessful exploitation gives total control of the vulnerable component.
CISA publishes the decision points, not a final SSVC decision. The decision also depends on mission and well-being impact, which is a property of your deployment rather than of the vulnerability.
EPSS probability
Not scored by EPSS
EPSS percentile
Not scored by EPSS
NVD base score
9.8 (CVSS v3.x), scored by the NVD independently of the CNA.
NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NVD analysis status
Received. NVD last modified this record on 2026-10-03.
Red Hat severity
No Red Hat rating. Red Hat rates the CVEs that affect its products.

Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.

04 Metadata

Published
2026-10-03 11:55Z10 HR AGO
Last updated
2026-10-03 15:52Z6 HR AGO
Reserved
2026-10-03
Assigning CNA
TuranSec
Record state
PUBLISHED
Severity
Critical (CVSS 9.8)
CNA CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
  • CWE-306Missing Authentication for Critical FunctionBase
Data version
5.2
Document digest
afd9dc0a8dad541afc5f9653f4d383d969c8052b7a71f06bd6a41b1572ed0810

05 Affected products

VendorProductVersionsPlatforms
NASA-AMMOSAIT-Core0 to 3.1.1—

06 References

07 Remediation

Upgrade to AIT-Core 3.1.2 or later. Version 3.1.2 changes the default ZeroMQ XSUB and XPUB bind addresses to loopback. Deployments that require the ZeroMQ message bus to operate across multiple hosts should protect the bus using authenticated and encrypted transport such as ZeroMQ CURVE or an equivalent mutually authenticated TLS-protected network layer.