CVE-2026-105105: CWE-306: Missing Authentication for Critical Function in NASA-AMMOS AIT-Core
CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message bus to inject spacecraft command data, exfiltrate command and telemetry traffic, inject forged telemetry, or disrupt the command and telemetry bus. The ait-server ZeroMQ broker binds its XSUB and XPUB sockets to all network interfaces by default without authentication or transport security. An attacker able to reach TCP port 5559 can publish messages onto internal topics, including the __commands__ command topic. With the shipped default configuration, command messages are forwarded through command_stream and emitted on the command-uplink UDP path. An attacker able to reach TCP port 5560 can subscribe to command and telemetry traffic on the ground bus. AIT-Core 3.1.2 changes the default ZeroMQ bind addresses to loopback.
AI Analysis
Technical Summary
The vulnerability identified as CVE-2026-105105 (CWE-306) affects the ait.core.server telemetry and command broker (ait-server) component of NASA-AMMOS AIT-Core through version 3.1.1. The ZeroMQ broker binds its XSUB and XPUB sockets to all network interfaces by default and does not implement authentication or transport security. This allows an unauthenticated remote attacker with network access to TCP ports 5559 and 5560 to publish unauthorized command messages, subscribe to command and telemetry traffic, inject forged telemetry data, exfiltrate sensitive command and telemetry information, or disrupt the command and telemetry bus. The default configuration forwards command messages through command_stream and emits them on the command-uplink UDP path. The vulnerability is mitigated in version 3.1.2 by changing the default ZeroMQ bind addresses to loopback, preventing remote network access.
Potential Impact
An unauthenticated remote attacker with network access to the ZeroMQ message bus can perform critical unauthorized actions including injecting spacecraft command data, exfiltrating command and telemetry traffic, injecting forged telemetry, and disrupting the command and telemetry bus. This compromises confidentiality, integrity, and availability of spacecraft command and telemetry communications, posing a severe risk to mission operations.
Mitigation Recommendations
A fix is available in NASA-AMMOS AIT-Core version 3.1.2, which changes the default ZeroMQ bind addresses to loopback only, effectively preventing remote network access to the message bus. Users should upgrade to version 3.1.2 or later to remediate this vulnerability. No other mitigation guidance is provided in the vendor advisory.
CVE-2026-105105: CWE-306: Missing Authentication for Critical Function in NASA-AMMOS AIT-Core
Description
CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message bus to inject spacecraft command data, exfiltrate command and telemetry traffic, inject forged telemetry, or disrupt the command and telemetry bus. The ait-server ZeroMQ broker binds its XSUB and XPUB sockets to all network interfaces by default without authentication or transport security. An attacker able to reach TCP port 5559 can publish messages onto internal topics, including the __commands__ command topic. With the shipped default configuration, command messages are forwarded through command_stream and emitted on the command-uplink UDP path. An attacker able to reach TCP port 5560 can subscribe to command and telemetry traffic on the ground bus. AIT-Core 3.1.2 changes the default ZeroMQ bind addresses to loopback.
CVSS v3.1
Score 9.8critical
Affected software
NASA-AMMOS
AIT-Core
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability identified as CVE-2026-105105 (CWE-306) affects the ait.core.server telemetry and command broker (ait-server) component of NASA-AMMOS AIT-Core through version 3.1.1. The ZeroMQ broker binds its XSUB and XPUB sockets to all network interfaces by default and does not implement authentication or transport security. This allows an unauthenticated remote attacker with network access to TCP ports 5559 and 5560 to publish unauthorized command messages, subscribe to command and telemetry traffic, inject forged telemetry data, exfiltrate sensitive command and telemetry information, or disrupt the command and telemetry bus. The default configuration forwards command messages through command_stream and emits them on the command-uplink UDP path. The vulnerability is mitigated in version 3.1.2 by changing the default ZeroMQ bind addresses to loopback, preventing remote network access.
Potential Impact
An unauthenticated remote attacker with network access to the ZeroMQ message bus can perform critical unauthorized actions including injecting spacecraft command data, exfiltrating command and telemetry traffic, injecting forged telemetry, and disrupting the command and telemetry bus. This compromises confidentiality, integrity, and availability of spacecraft command and telemetry communications, posing a severe risk to mission operations.
Mitigation Recommendations
A fix is available in NASA-AMMOS AIT-Core version 3.1.2, which changes the default ZeroMQ bind addresses to loopback only, effectively preventing remote network access to the message bus. Users should upgrade to version 3.1.2 or later to remediate this vulnerability. No other mitigation guidance is provided in the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- TuranSec
- Date Reserved
- 2026-10-03T11:45:52.353Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac0f22aa43b0b3b89bfb552
Added to database: 10/03/2026, 12:16:42 UTC
Last enriched: 10/03/2026, 12:31:05 UTC
Last updated: 10/03/2026, 21:45:56 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.