Description
Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal.
Published:
2026-08-03
Score:
n/a
EPSS:
n/a
KEV:
No
Impact:
n/a
Action:
n/a
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://github.com/nasa/cFS/issues/1072 |
|
History
Mon, 03 Aug 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nasa
Nasa cfs |
|
| Vendors & Products |
Nasa
Nasa cfs |
Mon, 03 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-03T21:57:30.683Z
Reserved: 2026-07-30T00:00:00.000Z
Link: CVE-2026-67970
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-03T23:30:17Z
Weaknesses
No weakness.