Back to advisories

NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

NASA's AIT-GUI spacecraft control software contains critical unauthenticated command injection vulnerabilities (CVSS 9.4) allowing attackers to execute arbitrary commands and scripts without authentication. Any organization running AIT-GUI versions below 2.5.2 is at immediate risk of losing control of spacecraft systems or connected instruments. The patched version exists but most deployed instances are still on vulnerable 2.4.1 from PyPI.