CVE-2025-25371: Path Traversal
Published Mar 25, 2025
·Updated
NASA cFS (Core Flight System) Aquila is vulnerable to path traversal in the OSAL module, allowing the override of any arbitrary file on the system.
Affected Software
2 affected components
nasa Core Flight System
nasa Core Flight System=6.7.0
Event History
Mar 25, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25371?
CVE-2025-25371 has a high severity rating due to its potential for unauthorized file access via path traversal.
2
How do I fix CVE-2025-25371?
To fix CVE-2025-25371, it is recommended to implement proper input validation to mitigate path traversal attacks in the OSAL module.
3
What systems are affected by CVE-2025-25371?
CVE-2025-25371 specifically affects the NASA Core Flight System Aquila version.
4
What is path traversal in the context of CVE-2025-25371?
Path traversal allows an attacker to access files outside the intended directory structure, potentially leading to sensitive file exposure or system compromise.
5
Are there any known exploits for CVE-2025-25371?
As of now, there are no publicly available exploits specifically targeting CVE-2025-25371.