IM
IronMonkey Threat Research
‹ Back to ICS Advisories

NASA Core Flight System (cFS) Health & Safety (HS) Application

HIGH
CVSS 7.5
Date 2026-07-30T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-18064 7.5 high
An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause the HS application to crash, resulting in a denial-of-service condition and processor reset.

// Remediations (2)

Mitigation: As an interim mitigation, users can update their HS app from the HS repo (https://github.com/nasa/HS
As an interim mitigation, users can update their HS app from the HS repo (https://github.com/nasa/HS) to the latest dev branch. The fix is in the dev branch starting at commit 828855f971db4b6714367ed0a970f52dbeab2965
Mitigation: NASA reports that an official fix is currently under development and is expected to be included in a
NASA reports that an official fix is currently under development and is expected to be included in a future software release.

// References