Cycode discloses unauthenticated command flaws in NASA AIT-GUI
Source headline: NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
Intelligence Summary
Cycode reported a chain of flaws in AIT-GUI, a browser-based operator console for NASA/JPL's AMMOS Instrument Toolkit. The issues could allow an unauthenticated attacker to issue arbitrary commands to the spacecraft and instrument command bus. The chain is tracked as GHSA-p9r8-2q67-fp86. It is rated 9.4 on the CVSS v3.1 scale. This combination suggests serious risk for operators relying on AIT-GUI. Update or patch AIT-GUI as advised by the vendor or maintainers and verify exposure is mitigated immediately.
Recommended Action
Check your exposure to GHSA-P9R8-2Q67-FP86 (CVSS 9.4) and apply the vendor fix once available. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.