Description
NASA AIT-Core v2.5.2 was discovered to use unencrypted channels to exchange data over the network, allowing attackers to execute a man-in-the-middle attack. When chained with CVE-2024-35059, the CVE in subject leads to an unauthenticated, fully remote code execution.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-qv6x-53jj-vw59 | NASA AIT-Core uses unencrypted channels to exchange data over the network |
References
History
Wed, 04 Jun 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nasa
Nasa ait Core |
|
| CPEs | cpe:2.3:a:nasa:ait_core:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nasa
Nasa ait Core |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T03:07:46.463Z
Reserved: 2024-05-09T00:00:00.000Z
Link: CVE-2024-35061
Updated: 2024-08-02T03:07:46.463Z
Status : Analyzed
Published: 2024-05-21T19:15:10.390
Modified: 2025-06-03T14:16:41.090
Link: CVE-2024-35061
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA