CVE-2024-35058: High severity nasa ait core vulnerability
Published May 21, 2024
·Updated
An issue in the API wait function of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via supplying a crafted string.
Affected Software
2 affected components
pip/ait-core<=2.5.2
nasa Ait Core<=2.5.2
Event History
May 21, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
via GitHub·06:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-35058?
CVE-2024-35058 is considered a critical vulnerability as it allows attackers to execute arbitrary code on affected systems.
2
How do I fix CVE-2024-35058?
To fix CVE-2024-35058, upgrade the AIT-Core package to a version later than 2.5.2.
3
What versions of AIT-Core are affected by CVE-2024-35058?
CVE-2024-35058 affects AIT-Core version 2.5.2 and earlier.
4
Can CVE-2024-35058 be exploited remotely?
Yes, CVE-2024-35058 can be exploited remotely, allowing attackers to execute arbitrary code from a distance.
5
What kind of attack is associated with CVE-2024-35058?
CVE-2024-35058 is associated with remote code execution attacks via the API wait function.