
Cloud Vulnerability DB
A community-led vulnerabilities database
NASA AIT-Core v2.5.2 was discovered to use unencrypted channels to exchange data over the network, allowing attackers to execute a man-in-the-middle attack. When chained with CVE-2024-35059, this vulnerability leads to an unauthenticated, fully remote code execution. The vulnerability was disclosed on May 21, 2024, and affects the ait-core package on pip repository versions 2.5.2 and below (NVD, GitHub Advisory).
The vulnerability is classified as CWE-311 (Missing Encryption of Sensitive Data). The CVSS v3.1 base score is 7.3 (HIGH) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L. The issue stems from the use of unencrypted ZeroMQ messaging for communication between processes, which makes it susceptible to man-in-the-middle attacks. The vulnerability becomes particularly severe when combined with CVE-2024-35059, which involves unsafe use of Python's Pickle library (LinkedIn Analysis).
The vulnerability allows attackers to intercept and modify network communications between AIT-Core components. When combined with CVE-2024-35059, it enables unauthenticated remote code execution. The impact affects confidentiality, integrity, and availability of the system, with each aspect rated as Low according to the CVSS metrics (GitHub Advisory).
The vulnerability is highly exploitable due to its network attack vector, low attack complexity, and no requirements for privileges or user interaction. An attacker can execute a man-in-the-middle attack to capture TCP frames and modify their content, potentially leading to remote code execution. The EPSS score indicates a 0.045% probability of exploitation within 30 days (GitHub Advisory).
As of the latest reports, there are no patched versions available. The recommended mitigations include replacing plain ZeroMQ communication with ZeroMQ SSH Tunneling, though this alone is insufficient. Additional security measures should be implemented to verify telemetry sources and prevent unauthorized connections (LinkedIn Analysis).
The vulnerability has garnered attention in the security community, particularly due to its impact on NASA's space mission control software. The discovery was made by researchers at VisionSpace, who have also identified several other severe vulnerabilities in AIT-Core v2.5.2, including SQL injection and multiple local code execution vulnerabilities (LinkedIn Analysis).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."