Core Flight System
Vendor:
First CVE: Mar 25, 2025 · Active for 1 year
8
Total CVEs
More Total CVEs than 85% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 46% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Core Flight System over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 25, 2025
15 months ago
Most Recent CVE
Apr 3, 2026
112 days ago
CVE Severity & Scoring
Core Flight System8 CVEs
25%
63%
13%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (12.5%)
Network4 (50.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network3 (37.5%)
Attack Complexity
Low6 (75.0%)
High2 (25.0%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (37.5%)
High0 (0.0%)
None5 (62.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-25373CRITICAL The Memory Management Module of NASA cFS (Core Flight System) Aquila has insecure permissions, which can be exploited to gain an RCE on the platform. | Mar 25, 2025 | 9.8 | 30 | NO | NO |
CVE-2026-5474HIGH A vulnerability was found in NASA cFS up to 7.0.0. This affects the function CFE_MSG_GetSize of the file apps/to_lab/fsw/src/to_lab_passthru_encode.c of the component CCSDS Packet | Apr 3, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-5473HIGH A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the component Pickle Module. Such manipulation leads to deserialization. | Apr 3, 2026 | 7.0 | 23 | NO | NO |
CVE-2025-25371HIGH NASA cFS (Core Flight System) Aquila is vulnerable to path traversal in the OSAL module, allowing the override of any arbitrary file on the system. | Mar 25, 2025 | 7.5 | 23 | NO | NO |
CVE-2025-25372HIGH NASA cFS (Core Flight System) Aquila is vulnerable to segmentation fault via sending a malicious telecommand to the Memory Management Module. | Mar 25, 2025 | 7.5 | 22 | NO | NO |
CVE-2026-5475MEDIUM A vulnerability was determined in NASA cFS up to 7.0.0. This impacts the function CFE_SB_TransmitMsg of the file cfe_sb_priv.c of the component CCSDS Header Size Handler. Executing | Apr 3, 2026 | 5.5 | 21 | NO | NO |
CVE-2025-25374HIGH In NASA cFS (Core Flight System) Aquila, it is possible to put the onboard software in a state that will prevent the launch of any external application, causing a platform denial o | Mar 25, 2025 | 7.5 | 21 | NO | NO |
CVE-2026-5476MEDIUM A vulnerability was identified in NASA cFS up to 7.0.0 on 32-bit. Affected is the function CFE_TBL_ValidateCodecLoadSize of the file cfe/modules/tbl/fsw/src/cfe_tbl_passthru_codec. | Apr 3, 2026 | 4.6 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Core Flight System
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.7.0 | 4 | 8.1 | 0.5% | 0 | 0 |