NASA's ground control software has a worrying security flaw which could let hackers contact spacecraft
- NASA’s ground control software has a critical vulnerability that could allow third-party access to spacecraft
- The flaw has been found in a browser-based variant of NASA’s AMMOS Instrument Toolkit
- NASA has not publicly responded to the flaw’s disclosure
NASA’s open source ground control software has a critical vulnerability that could enable an unauthenticated attacker to gain access and take control of spacecraft. The AMMOS Instrument Toolkit’s browser-based interface is the source of the vulnerability, which has since been resolved.
The AIT-GUI (AMMOS Instrument Toolkit Graphical User Interface) tool up to version 2.5.1 has been identified as vulnerable, but the fault has been fixed in v2.5.2, according to researcher Yuval Elbar.
If the vulnerability had been found by a third party, it would have given access to issue commands to spacecraft, instruments, and execute server-side scripts. In addition, command sequences could potentially have been run by an attacker, leaving craft almost...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE