GHSL-2024-129: GHSL-2024-127_GHSL-2024-129: Remote Code Execution (RCE) via Cross-Site Scripting (XSS) in OpenC3 COSMOS - CVE-2024-43795, CVE-2024-46977, CVE-2024-47529
Several vulnerabilities were found in OpenC3 COSMOS, a web application that is used to control satellites and test equipment. They can lead up to Remote Code Execution (RCE) via cross-site scripting (XSS).
Affected Software
Event History
Frequently Asked Questions
What is the severity of GHSL-2024-129?
The severity of GHSL-2024-129 is rated at 77, indicating a significant risk of Remote Code Execution.
How do I fix GHSL-2024-129?
To fix GHSL-2024-129, you should update OpenC3 COSMOS to the latest version available that addresses these vulnerabilities.
What are the main vulnerabilities associated with GHSL-2024-129?
GHSL-2024-129 is associated with multiple vulnerabilities including CVE-2024-43795, CVE-2024-46977, and CVE-2024-47529.
Can GHSL-2024-129 lead to security breaches?
Yes, GHSL-2024-129 can lead to serious security breaches through Remote Code Execution via Cross-Site Scripting.
What is the impact of not addressing GHSL-2024-129?
Failing to address GHSL-2024-129 can result in unauthorized access to sensitive systems and potential control over satellite operations.