Unauthenticated Remote Code Execution in NASA AMMOS AIT-GUI 2.5.0 via /tlm/query file write chained to /script/run code execution

Disclosed by
ward0
Summary by ward0

Unauthenticated Remote Code Execution in NASA AMMOS AIT-GUI 2.5.0

An unauthenticated remote code execution vulnerability was identified in NASA AMMOS AIT-GUI 2.5.0.

The issue resulted from a chain involving unauthenticated access to the /tlm/query endpoint, attacker-controlled file creation, and insufficient path validation in /script/run, allowing attacker-controlled Python code to be executed by the AIT-GUI process.

The vulnerability was reproduced against a self-hosted instance of AIT-GUI 2.5.0 without accessing NASA production systems. The issue was reported through the NASA Vulnerability Disclosure Program, successfully validated by Bugcrowd, and subsequently resolved by the program.

CVSS v3.1: 9.8 (Critical)

The vulnerability could allow a remote unauthenticated attacker who can reach an exposed AIT-GUI service to execute arbitrary operating-system commands with the privileges of the application process.

Activity