The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089) with elevated capabilities, bypassing the CAM gateway that is the system's sole authentication boundary. The underlying REST server, implemented with CivetWeb, is configured without authentication [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T08:16:43.807Z and has not been modified since then. The Aerie/PlanDev sequencing-server's authorization middleware derives the caller's Hasura session role via getHasuraSession(), which prefers a session_variables object taken directly from the client-supplied JSON request body over the Authoriza [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-29T16:17:55.560Z and has not been modified since then. The AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before version 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager. This allows unauthenticated network attackers to acce [truncated]
AIT GUI before 2.5.1 has a missing authentication vulnerability allowing unauthenticated network attackers to obtain valid sessions and issue arbitrary spacecraft commands. This vulnerability enables attackers to bypass authentication mechanisms and gain unauthorized access to the system. Organizations should be aware of the potential risks and take necessary actions to mitigate the vulnerability. The vul [truncated]
The AMMOS Instrument Toolkit (AIT-Core) is vulnerable to a critical path traversal and arbitrary file append attack due to a lack of proper validation of path-related form fields in the Binary Stream Capture (BSC) component. This issue affects BSC (Binary Stream Capture) and usage of the ait-bsc server, impacting AIT-Core versions before 3.1.1 and 2.x before 2.6.1. The vulnerability allows a remote client [truncated]