Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2024-35061
Python vulnerability analysis and mitigation

Overview

NASA AIT-Core v2.5.2 was discovered to use unencrypted channels to exchange data over the network, allowing attackers to execute a man-in-the-middle attack. When chained with CVE-2024-35059, this vulnerability leads to an unauthenticated, fully remote code execution. The vulnerability was disclosed on May 21, 2024, and affects the ait-core package on pip repository versions 2.5.2 and below (NVD, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-311 (Missing Encryption of Sensitive Data). The CVSS v3.1 base score is 7.3 (HIGH) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L. The issue stems from the use of unencrypted ZeroMQ messaging for communication between processes, which makes it susceptible to man-in-the-middle attacks. The vulnerability becomes particularly severe when combined with CVE-2024-35059, which involves unsafe use of Python's Pickle library (LinkedIn Analysis).

Impact

The vulnerability allows attackers to intercept and modify network communications between AIT-Core components. When combined with CVE-2024-35059, it enables unauthenticated remote code execution. The impact affects confidentiality, integrity, and availability of the system, with each aspect rated as Low according to the CVSS metrics (GitHub Advisory).

Exploitability

The vulnerability is highly exploitable due to its network attack vector, low attack complexity, and no requirements for privileges or user interaction. An attacker can execute a man-in-the-middle attack to capture TCP frames and modify their content, potentially leading to remote code execution. The EPSS score indicates a 0.045% probability of exploitation within 30 days (GitHub Advisory).

Mitigation and workarounds

As of the latest reports, there are no patched versions available. The recommended mitigations include replacing plain ZeroMQ communication with ZeroMQ SSH Tunneling, though this alone is insufficient. Additional security measures should be implemented to verify telemetry sources and prevent unauthorized connections (LinkedIn Analysis).

Community reactions

The vulnerability has garnered attention in the security community, particularly due to its impact on NASA's space mission control software. The discovery was made by researchers at VisionSpace, who have also identified several other severe vulnerabilities in AIT-Core v2.5.2, including SQL injection and multiple local code execution vulnerabilities (LinkedIn Analysis).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61599HIGH8.8
  • Python logoPython
  • djust
NoYesSep 16, 2026
CVE-2026-61596HIGH7.1
  • Python logoPython
  • djust
NoYesSep 16, 2026
CVE-2026-61588MEDIUM6.5
  • Python logoPython
  • djust
NoYesSep 16, 2026
CVE-2026-61589MEDIUM6.3
  • Python logoPython
  • djust
NoYesSep 16, 2026
CVE-2026-61597MEDIUM5.1
  • Python logoPython
  • djust
NoYesSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management