CVE-2026-71289: CWE-306 in NASA-AMMOS anms
CVE-2026-71289 is a critical vulnerability in the NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation. The default docker-compose.yml configuration exposes the amp-manager service's REST API directly on the host network interface without proper authentication. The REST server disables domain authentication checks and registers all routes with a null authentication callback, allowing any network client to enumerate agents, send arbitrary commands, and clear reports without credentials. This affects the reference implementation and testbed components communicating with DTNMA agents, which may represent simulated or real spacecraft or ground nodes.
AI Analysis
Technical Summary
The vulnerability arises from the default deployment of NASA-AMMOS ANMS where the amp-manager REST API is exposed directly on the host network interface (port 8089) with elevated Linux capabilities (NET_ADMIN, NET_RAW, SYS_NICE). The REST server, implemented with CivetWeb in the JHUAPL/dtnma-tools repository, has authentication disabled (enable_auth_domain_check set to "no") and registers all routes with a null authentication callback. This allows any network-reachable client to enumerate registered DTNMA agents, submit EXECSET-encoded command sets to them, and clear stored reports without any authentication. The affected components are reference implementations and testbeds, not flight software onboard spacecraft.
Potential Impact
An unauthenticated remote attacker can fully control the amp-manager REST API, including enumerating agents, sending arbitrary commands to DTNMA agents, and clearing stored reports. This leads to complete compromise of the network management system's integrity, confidentiality, and availability. Given the critical CVSS score of 9.8, the impact includes potential full system control and disruption of network management operations for simulated or real spacecraft/ground nodes in the affected deployments.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid exposing the amp-manager REST API directly to untrusted networks. Restrict network access to the service, enable authentication mechanisms if configurable, and do not deploy the default docker-compose.yml configuration in production environments. Monitor vendor channels for updates and apply official patches once released.
CVE-2026-71289: CWE-306 in NASA-AMMOS anms
Description
CVE-2026-71289 is a critical vulnerability in the NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation. The default docker-compose.yml configuration exposes the amp-manager service's REST API directly on the host network interface without proper authentication. The REST server disables domain authentication checks and registers all routes with a null authentication callback, allowing any network client to enumerate agents, send arbitrary commands, and clear reports without credentials. This affects the reference implementation and testbed components communicating with DTNMA agents, which may represent simulated or real spacecraft or ground nodes.
CVSS v3.1
Score 9.8critical
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises from the default deployment of NASA-AMMOS ANMS where the amp-manager REST API is exposed directly on the host network interface (port 8089) with elevated Linux capabilities (NET_ADMIN, NET_RAW, SYS_NICE). The REST server, implemented with CivetWeb in the JHUAPL/dtnma-tools repository, has authentication disabled (enable_auth_domain_check set to "no") and registers all routes with a null authentication callback. This allows any network-reachable client to enumerate registered DTNMA agents, submit EXECSET-encoded command sets to them, and clear stored reports without any authentication. The affected components are reference implementations and testbeds, not flight software onboard spacecraft.
Potential Impact
An unauthenticated remote attacker can fully control the amp-manager REST API, including enumerating agents, sending arbitrary commands to DTNMA agents, and clearing stored reports. This leads to complete compromise of the network management system's integrity, confidentiality, and availability. Given the critical CVSS score of 9.8, the impact includes potential full system control and disruption of network management operations for simulated or real spacecraft/ground nodes in the affected deployments.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid exposing the amp-manager REST API directly to untrusted networks. Restrict network access to the service, enable authentication mechanisms if configurable, and do not deploy the default docker-compose.yml configuration in production environments. Monitor vendor channels for updates and apply official patches once released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- TuranSec
- Date Reserved
- 2026-08-05T12:23:34.968Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7336e7bf8831d539ed92f6
Added to database: 08/05/2026, 13:13:11 UTC
Last enriched: 08/05/2026, 13:26:40 UTC
Last updated: 08/05/2026, 13:56:19 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.