BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

News Vulnerability
VulnerabilityCISA·12d ago

NASA Core Flight System (cFS) Health & Safety (HS) Application

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-03.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. /strong /p p The following versions of NASA Core Flight System (cFS) Health amp; Safety (HS) Application are affected: /p ul li Core Flight System (cFS) Health amp; Safety (HS) Application /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7.5 /td td NASA /td td NASA Core Flight System (cFS) Health amp; Safety (HS) Application /td td NULL Pointer Dereference /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Transportation Systems /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-15352 /a /h3 div class="csaf-accordion-content" p A vulnerability exists in the Health amp; Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request, leading to denial of service. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-15352" View CVE Details /a /p hr h4 Affected Products /h4 h5 NASA Core Flight System (cFS) Health amp; Safety (HS) Application /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br NASA /div div class="ics-version" strong Product Version: /strong br NASA Core Flight System (cFS) Health amp; Safety (HS) Application: lt;v7.0.1 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Mitigation /strong br NASA recommends users update to v7.0.1 (https://github.com/nasa/HS/releases/tag/v7.0.1) br a href="https://github.com/nasa/HS/releases/tag/v7.0.1" https://github.com/nasa/HS/releases/tag/v7.0.1 /a /p /div p strong Relevant CWE: /strong a href="https://cwe.mitre.org/data/definitions/476.html" CWE-476 NULL Pointer Dereference /a /p hr h4 Metrics /h4 div class="csaf-table csaf-metrics-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS Version /th th role="columnheader" Base Score /th th role="columnheader" Base Severity /th th role="columnheader" Vector String /th /tr /thead tbody tr td 3.1 /td td 7.5 /td td HIGH /td td a hre

Sign in to read the full article

Create a free account to access all news, downloads, and community features

Originally published by CISA

Source: https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-03

This article is shared for informational purposes. All rights belong to the original author and publisher. If you are the copyright holder and would like this content removed, please contact us.

Shared on IT-Hub by admin