simplysecuregroup.com • 6h
Critical Authentication Bypass in NASA AIT-GUI
A critical authentication bypass vulnerability (GHSA-p9r8-2q67-fp86) has been identified in the NASA/JPL AMMOS Instrument Toolkit GUI (AIT-GUI), a browser-based console used for spacecraft operations. The flaw stems from a failure to enforce authentication on the software's command bus, allowing unauthenticated remote attackers to bypass login requirements entirely. This vulnerability enables the issuance of arbitrary commands, execution of command sequences, and the running of arbitrary scripts directly against spacecraft and scientific instruments. With a CVSS v3.1 score of 9.4, this flaw represents an existential threat to mission integrity and the operational control of space assets.