CVE-2018-1000048: High severity nasa rtretrievalframework vulnerability
Published Feb 9, 2018
·Updated
NASA RtRetrievalFramework version v1.0 contains a CWE-502 vulnerability in Data retrieval functionality of RtRetrieval framework that can result in remote code execution. This attack appear to be exploitable via Victim tries to retrieve and process a weather data file.
Affected Software
1 affected component
nasa RtRetrievalFramework=1.0
Event History
Feb 9, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for NASA RtRetrievalFramework version v1.0?
The vulnerability ID for NASA RtRetrievalFramework version v1.0 is CVE-2018-1000048.
2
What is the severity of CVE-2018-1000048?
The severity of CVE-2018-1000048 is high with a severity value of 8.8.
3
What is the CWE ID for the vulnerability in NASA RtRetrievalFramework version v1.0?
The CWE ID for the vulnerability in NASA RtRetrievalFramework version v1.0 is CWE-502.
4
How does the vulnerability in NASA RtRetrievalFramework version v1.0 impact the system?
The vulnerability in NASA RtRetrievalFramework version v1.0 can result in remote code execution.
5
Is there a fix available for the vulnerability in NASA RtRetrievalFramework version v1.0?
There is no specific fix mentioned, but updating to a patched version or applying the suggested mitigations may help address the vulnerability.