CVE-2024-35061: High severity nasa ait core vulnerability
Published May 21, 2024
·Updated
NASA AIT-Core v2.5.2 was discovered to use unencrypted channels to exchange data over the network, allowing attackers to execute a man-in-the-middle attack.
Affected Software
2 affected components
pip/ait-core<=2.5.2
nasa Ait Core<=2.5.2
Event History
May 21, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
via GitHub·09:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-35061?
CVE-2024-35061 has been classified as a high severity vulnerability due to its potential for facilitating man-in-the-middle attacks.
2
How do I fix CVE-2024-35061?
To fix CVE-2024-35061, upgrade to a version of NASA AIT-Core higher than v2.5.2 that utilizes encrypted channels for data transmission.
3
What types of attacks can exploit CVE-2024-35061?
CVE-2024-35061 can be exploited primarily through man-in-the-middle attacks that intercept unencrypted data exchanges.
4
Is CVE-2024-35061 present in earlier versions of NASA AIT-Core?
Yes, CVE-2024-35061 affects all versions of NASA AIT-Core up to and including v2.5.2.
5
How can I determine if I am affected by CVE-2024-35061?
You can determine if you are affected by CVE-2024-35061 by checking if you are using NASA AIT-Core v2.5.2 or earlier.